Project for Privacy and Surveillance Accountability (PPSA)
  • TAKE ACTION
    • Section 702 Reform
    • PRESS Act
    • DONATE
  • Issues
  • Solutions
  • SCORECARD
    • Congressional Scorecard Rubric
  • News
  • About
  • TAKE ACTION
    • Section 702 Reform
    • PRESS Act
    • DONATE
  • Issues
  • Solutions
  • SCORECARD
    • Congressional Scorecard Rubric
  • News
  • About

 NEWS & UPDATES

Germany Shows That Governments Can Secretly Link to Your Encrypted Messaging Accounts

9/16/2026

 
Picture
If you rely on encrypted messaging services, take note: German authorities have found a way to read messages on WhatsApp, Signal, and Telegram without breaking the services’ encryption.

According to the Netzpolitik news site (you can select an English language version on most browsers), German law-enforcement and intelligence agencies exploit the services’ legitimate “linked device” features, which allow users to access their accounts from computers and other devices. Authorities can quietly connect a government-controlled computer to a targeted account after gaining physical access to a phone, obtaining a verification code through phishing, or intercepting an SMS code.

Once connected, authorities can receive future messages and – depending on the service – access earlier messages, contacts, and other account information. In some cases, the linked device can even send messages in the user’s name. Users may remain unaware because encryption remains intact. The government does all this by simply placing itself at one of the authorized endpoints.

German customs authorities reportedly tested this technique beginning in 2023 and made it a permanent investigative tool in 2025 after claiming significant successes against serious and organized crime. Its legal basis, even in surveillance-friendly Germany, remains disputed.

There is little reason to believe the German government is the only one doing this. Cybernews warns that the technique uses readily available functions built into popular apps. Does the FBI have this capability? That might be a good question for someone in Congress to ask.

Given this exposure, what can you do to protect your privacy?
​

When you sign on to an encrypted account, take a few seconds to review the devices linked to your account. Immediately remove any you do not recognize. Strong encryption protects communications in transit. It cannot protect users when a government – or hacker – is secretly inside a seemingly authorized endpoint.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

AI Makes Authoritarian Surveillance Cheaper, Faster, and More Powerful

9/15/2026

 
Picture
How’s this for a prompt for ChatGPT or Claude: “Give me a list of people who’ve criticized the regime in the last several months.”

Artificial intelligence helps small teams accomplish work that once required large organizations. Unfortunately, that now includes secret police units in repressive regimes around the world.

According to the London-based, dissident-run Iran International news site, the AI company Anthropic discovered that Iranian paramilitary and security units had used its Claude AI model to monitor Iranians’ social media posts to identify opposition and diaspora accounts.

One Iranian unit analyzed hundreds of thousands of social-media posts and identified 39 opposition accounts to track. Other actors used Claude to develop tools for identifying and profiling users, including a malicious Firefox extension disguised as a prayer-times utility.

Iranian units also used Claude to develop or improve a centralized surveillance case-management system. AI was not merely collecting information. It was helping the state organize its surveillance bureaucracy and decide whom to watch.

The stakes of Iran’s domestic surveillance are deadly. Medical networks, whistleblowers, and unofficial leaks estimate that thousands of Iranian dissidents and protesters, most of them young men and women, have been killed in the streets or executed just before the beginning of the U.S.-Iranian war earlier this year.

To its credit, Anthropic has aggressively countered this misuse of its product. In the Iranian operations, it identified and unplugged 16 Claude accounts operated by two units associated with Iranian paramilitary and domestic security agencies.

Iran is far from alone in its authoritarian abuse of AI. Axios reports that government-linked actors in China and Mali have also used Claude to automate surveillance.

A consultant working for Malian security authorities reportedly created a system that gathers information from mobile operators and builds dossiers on individuals. In China, an intelligence office dedicated to spying on religious organizations once required large teams of analysts in many offices. AI consolidated it to a single office capable of producing thousands of investigations each month. Chinese authorities also used Claude to evaluate politically sensitive social-media posts and identify people for “control” – potentially including coercive questioning and closer monitoring of their movements and communications.

Anthropic says it banned every account associated with the surveillance operations that it uncovered and strengthened its safeguards. But the company acknowledges the limits of any response. In the case of Mali, authorities simply transferred their surveillance platform to locally operated AI models.

The danger is therefore larger than one company or chatbot. As Anthropic threat-intelligence chief Jacob Klein told Axios, AI is making state surveillance cheaper and more efficient. A lone official or contractor can increasingly perform work that once required whole teams of programmers and intelligence analysts.

Authoritarian governments have always wanted to monitor dissidents, journalists, religious minorities, and political opponents. AI is abolishing the practical constraints that once limited human surveillance.

George Orwell’s nightmare vision of totalitarian surveillance in 1984 always faced the practical constraint of recruiting enough watchers to monitor people around the clock. For every subversive comment or passed note, the watchers of 1984 would have had to sit through thousands of hours of people eating breakfast, brushing their teeth, and walking to work.
​

But AI repression doesn’t get bored. It needs no lunch breaks or naps. And it is here.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Former Police Chief Proposes Guardrails for Flock – Are They Enough?

9/14/2026

 
Picture
Flock Safety cameras and other automated license-plate reader (ALPR) systems have become a national flashpoint in debates over surveillance, policing, and privacy. Even data centers poll better than Flock cameras.
 
Now a former police chief is proposing a detailed framework intended to preserve the investigative uses of Flock and other ALPR systems while imposing new rules governing how police departments operate them.
 
Tom Weitzel, who served as police chief in Riverside, Illinois, has released a position paper on automated license plate reader systems, including the cameras made by Flock Safety. Weitzel, a 37-year law-enforcement veteran, writes that he has seen technology improve policing – and seen its misuse damage public trust.
 
In a letter published by Patch, Weitzel explains what prompted his proposal:
 
“I keep watching the debate and feel stuck between two bad options: leave these systems running with no real oversight or rip them out altogether. I don’t accept either option. I’ve seen ALPR data recover stolen vehicles, locate missing people, and crack violent crime cases that otherwise would have gone cold. Walking away from that capability doesn’t make anyone safer.
 
“At the same time, I won’t defend a system that can’t demonstrate it’s being used honestly.”
 
Weitzel proposes that communities adopt:
​
  • An independent civilian oversight board with subpoena power
 
  • Mandatory written justification and case numbers for every search
 
  • Immutable audit logs
 
  • A 30-day retention limit for data that does not produce a “hit” on an investigative “hot list.”
 
  • A public discipline matrix with zero tolerance for personal misuse.
​
We note that Weitzel’s suggested 30-day retention period for “non-hit” data – images of vehicles not related to any law-enforcement hot list – exceeds the 7-day retention period now recommended by Flock CEO Garrett Langley. We would also recommend including an explicit prohibition against tracking individuals solely on the basis of their religious, political, or journalistic activity protected by the First Amendment.
 
His paper also proposes transparency measures, including a dashboard that reports aggregate searches, criminal-activity hits, usage audits, and disciplinary actions against officers. He proposes a public portal called “Explain My Stop,” and the selection of community members by lottery to participate in audits.
 
Weitzel would also institute an annual “State of Surveillance” town hall and independent academic reviews. Other elements include a plain-language explanation of ALPR policies, public accounts of cases solved with ALPR assistance, optional alerts for residents whose plates are searched repeatedly, and independent compliance certification for programs.
 
Weitzel’s framework provides a detailed set of ideas for lawmakers in Congress and state legislatures, police departments, and communities to consider as they debate whether – and under what conditions – to continue using ALPR systems

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

How Federal Financial Surveillance Becomes a Backdoor to Pretextual Traffic Stops

9/14/2026

 
Picture
Imagine you get pulled over, a police officer walks up to your window and asks:

“Did you know your taillight is broken?”

-or-

“I pulled you over because you were weaving between lanes.”

-or-

“You didn’t come to a complete stop at the stop sign.”

-But never-

“I pulled you over because the federal government, which monitors your financial transactions, wonders if you might be engaged in illicit activity and wanted me to come up with a BS excuse to pull you over and find a reason to search your car.”

We’ve long reported that federal agents are mining our private financial information to identify Americans for investigation – even when they are not suspected of any particular crime.

In a disturbing investigation for 404 Media, Joseph Cox reveals that secretive predictive-policing units within the U.S. Border Patrol are analyzing Americans’ financial activity and other data. Federal agents pass their suspicions to local police, who then spot the targeted Americans in their cars and look for traffic violations and other opportunities to obtain consent to search their vehicles.

This arrangement turns financial surveillance into a backdoor predicate for police encounters. Federal agents need not begin with evidence that someone committed a crime. An algorithm or analyst merely decides that a person’s spending or other activities look interesting. Police officers can then look for a broken taillight, an improper lane change, or some equally flimsy excuse to pull that person over.

This practice reverses the constitutional order. Under the Fourth Amendment, law enforcement is supposed to begin with individualized suspicion and obtain a warrant when a search requires one. Predictive policing begins with mass data, generates an opaque hunch, and then goes looking for a violation to justify an investigation that is secretly already underway.

These reported abuses demonstrate why financial privacy cannot be dismissed on the theory that bank records are merely business records. Financial data can provide the government with a detailed map of a person’s life. When combined with location information – perhaps from automated license plate readers like those provided by Flock Safety – purchased commercial databases, and other digital records, financial information provides the raw material for suspicionless surveillance.

The partnership between federal analysts and local police adds another layer of abuse by obscuring the true origin of an investigation. Courts, defense attorneys, and defendants may see only a routine traffic stop, never knowing about the federal data dragnet operating behind it.

Congress should demand full disclosure of these units’ sources, methods, targeting criteria, and coordination with local police. It should also require warrants for Americans’ sensitive financial information and prohibit federal agencies from laundering suspicionless surveillance through pretextual stops.
​

Credit to Joseph Cox and 404 Media for exposing this machinery.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

House Passes Landmark Reform of Government Surveillance Gag Orders

9/1/2026

 
Picture
The U.S. House of Representatives today passed the NDO Fairness Act by voice vote, delivering a major victory for privacy, due process, and government accountability.

Credit goes to Rep. Scott Fitzgerald (R-WI), who sponsored this bipartisan reform with Rep. Jerry Nadler (D-NY), as well as with support from Judiciary Chairman Jim Jordan (R-OH) and Ranking Member Jamie Raskin (D-MD). Rep. Fitzgerald has persistently championed the bill through several Congresses, recognizing that Americans should not be kept forever in the dark when the government obtains their private digital records.

Under current law, prosecutors can secretly demand a person’s emails, messages, photographs, location history, and other sensitive information from a communications or cloud provider. They can then seek a nondisclosure order – really, a gag order – preventing the provider from notifying its customer. Such orders can continue indefinitely, leaving people with no opportunity to challenge improper surveillance.

The NDO Fairness Act brings this secretive process under meaningful judicial control.

Under the act, an initial gag order for most investigations could last no longer than 90 days. Any extension would be limited to another 90 days and would require a court to make renewed written findings based on “specific and articulable facts.” The court would also have to find that the gag is narrowly tailored and that no less restrictive alternative would protect the investigation, witnesses, evidence, or public safety.

Most importantly, once the gag expires, the government – not the communications provider – would generally have five business days to notify the person whose information was sought. That notice must describe the inquiry, identify the court that authorized the secrecy, and disclose that the government requested or received the person’s records. The individual could also request a copy of the information disclosed.

“As PPSA has long maintained, notice is essential to accountability,” said Bob Goodlatte, former Chairman of the House Judiciary Committee and PPSA Senior Policy Advisor. “A right that can be violated forever in secret is almost impossible to defend.
​

“The House has acted and the Senate should now take up the NDO Fairness Act and send it to the president’s desk,” he said. “Americans deserve and can have both security and transparency. This bill advances both.”

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Critical Questions for Sen. Hawley to Ask in His Much-Needed Investigation into Flock’s National Surveillance Network

8/31/2026

 
Picture
PICTURED: U.S. Sen. Josh Hawley, R-Mo
Sen. Josh Hawley (R-MO), chairman of the Senate Judiciary Subcommittee on Crime and Counterterrorism, has launched a welcome investigation into Flock Safety’s vast network of automated license plate readers.
 
In a letter to Flock CEO Garrett Langley, Sen. Hawley writes:
 
“In a few short years, Flock has assembled an unprecedented national surveillance network. Your company boasts more than 120,000 cameras across 49 states and more than 20 billion vehicle scans every month. The overwhelming majority of the Americans captured in those records did nothing wrong.”
 
Sen. Hawley adds that, instead of supporting discrete investigations, Flock’s camera data can be harnessed by artificial intelligence “to pool what they capture into a national database that customers can search.”
 
PPSA commends Sen. Hawley for recognizing what a departure from American privacy norms Flock’s technology represents. Flock cameras record the movements of millions of innocent drivers. How that information is collected, stored, searched, shared, and ultimately used should not be governed solely by corporate policies and thousands of customized contracts with police departments scattered across the country.
 
As Sen. Hawley writes:
 
“Americans do not surrender their privacy rights when they drive to work, drop their kids off at school, or go to church. The Supreme Court has recognized that a comprehensive, retrospective record of a person’s movements is different in kind from ordinary observation in public. Congress never authorized the network your industry has built.”
 
The investigation should closely examine how government access to Americans’ movements works – and the potential for that access to evolve into practices we associate with China’s surveillance state. Under Flock’s contracts, state and local police departments generally own the data their cameras generate. How do they use that data?
 
Here are questions for Sen. Hawley and his colleagues to ask:

  • Are federal agencies buying, requesting, or otherwise acquiring that information from state and local law enforcement agencies?

  • Are state-federal “fusion centers” providing another route by which locally collected data enters federal databases or investigations?

  • Beyond Flock Safety’s recommendations, what are the longest periods for which state and local customers are retaining Flock data?
    ​

  • Has any customer ever used Flock data to track political, journalistic, or religious activities protected by the First Amendment?
 
As Sen. Hawley concludes, “the American people want to know who has access to their personal data and how.”
 
Americans deserve to know whether such arrangements allow federal agencies to evade constitutional and statutory safeguards. This investigation should provide those answers – and set the foundation for national standards governing Flock data. At least two safeguards should emerge from this investigation.
 
An explicit prohibition is needed to prevent Flock data from being used to track Americans’ First Amendment activities.
 
Standards should also include strict limits on collection, retention, sharing, and secondary uses, as well as a clear requirement that police obtain a probable-cause warrant before using Flock’s network to track an American’s movements.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Flock Safety CEO Promises “Guardrails” and Vows to Avoid Moving “Recklessly” into “Dangerous” Technologies

8/24/2026

 
Picture
​The threats to personal privacy posed by Flock Safety’s national network of 120,000 automated license plate readers (ALPRs) are generating national pushback. As dozens of communities cancel their contracts with Flock – and Sen. Bernie Sanders (D-VT) calls on Congress to ban Flock – the company’s CEO, Garrett Langley, is undertaking a charm offensive to defend his product by pointing to the technology’s benefits.

In a Saturday interview on Fox News with Kayleigh McEnany, Langley said Flock’s network has helped locate 10,000 missing persons. He claimed that if Flock cameras had been in the right part of Arizona, the disappearance of Nancy Guthrie would not be a mystery.

The Need for Guardrails

Langley said that two priorities must be followed in future regulation. The first priority is to put limits on police departments’ retention of Flock data. Langley said we should all ask, “So how long is this data stored?” Flock now recommends a default retention period of seven days. Langley noted that this is a tighter standard than the 21-day limit imposed by the strictest state legislation.

The second priority, Langley said, is “accountability” for abuses of this technology by a few bad apples in law enforcement.

“Today, it is too often that in Flock and other technologies, there is no regulation. There is no accountability. And we think that’s wrong.”

In response to recent stories about police officers misusing Flock for stalking, Langley pointed to Flock’s change to an “audit assistance tool,” which monitors the ways in which Flock is used.

Flock and AI

McEnany asked Langley about a Wired report on the integration of a powerful new AI tool that allows Flock’s system to use ALPR data and other records to identify drivers (and, by implication, their movements and associations).

Langley acknowledged that AI is “incredibly powerful, but also a very dangerous tool.” He promised not to move “recklessly” into AI. “It requires more third-party attestation; more support from the community.”

Langley added that a consumer might be irritated by an AI agent that flubs a flight reservation. But when one calls 911, he said, “it has to work. There’s no space for hallucinations.”

Langley pledged to seek community support to confirm that AI has appropriate “guardrails.”

Promises Made, But How Will They Be Implemented?

It is a welcome sign that Flock’s CEO acknowledges that his technology needs guardrails and regulation – an implicit admission that its unregulated use poses risks to Americans’ privacy.

It is also a welcome sign that Langley acknowledges that AI is a “dangerous tool” and that it must operate with near-perfect accuracy.

The devil – if not a host of devils – is in the myriad details. For example, the ACLU questions whether Flock’s new audit tool could boomerang and expand surveillance. And the guardrails for AI are, as of today, speculative.

It is not enough to eliminate false positives that could misidentify innocent people as suspects to be targeted by law enforcement. The combination of AI and Flock technology is precisely the kind of tool that enables the surveillance state of the People’s Republic of China.

Congress should consider a law that prohibits federal and state agencies from using AI to search ALPR databases in order to track Americans’ daily movements without a probable-cause warrant.

Otherwise, our daily lives and associations – personal, romantic, political, commercial, and religious – will be an open book.
​
But we should all welcome Langley’s openness to further discussion.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

The Deep State that Cried Wolf

8/23/2026

 
Picture
The lapse in the reauthorization of Section 702 of the Foreign Intelligence Surveillance Act was a crisis until it wasn’t.

This surveillance law authorizes federal intelligence agencies to spy on foreign threats on foreign soil. But it has also been used by the FBI to snoop on the communications of Americans who are suspected of no crime and whose communications were incidentally swept up in the National Security Agency’s global maw. Millions of such searches have been conducted in recent years.

Reform-minded Members of Congress, troubled by these mass, unrestrained searches of Americans, sought to add a warrant requirement to Section 702 before the government could read Americans’ communications at will. They were stopped by an unprecedented shutdown of regular order that prevented any debate on even modest reform amendments.

As a result, Congress deadlocked and Section 702’s reauthorization expired in late spring. Dire predictions were made about the consequences of Section 702 “going dark.”

  • Sen. Tom Cotton (R-AK) said that without a “short-term extension of this legislation, especially as we begin welcoming literally millions of foreigners to this country for the World Cup and for the American 250 celebrations right around the corner … the consequences, to be frank, could be fatal.”
 
  • Rep. Jim Himes (D-CT): “I cannot in good conscience allow this program to expire and once again leave Americans vulnerable to national security threats like the terrorist attack that took the lives of 161 precious residents of Connecticut on September 11, 2001.”

Well, the World Cup and Fourth of July celebrations came and went with no terrorist attacks. The eight men who were apprehended around that time for allegedly planning to disrupt the White House UFC event on the White House grounds were caught after warrants were issued following a tip to law enforcement from one suspect’s mother.

To be clear, we do not by any means dismiss the ever-present threat of terrorism, especially with Iran now making lurid threats against the president, his family, and the American people.

Our point is that it was well known on Capitol Hill that Section 702 had only expired as a governing statute. But the secret FISA Court had already approved “certifications,” or surveillance orders targeting terrorists and foreign threats under Section 702, that will “keep the lights on” through March 2027.

So Section 702 never went dark. The intelligence community is still using it as it always has. If a terrorist attack occurs between now and March, it won’t be because the NSA, CIA, and FBI are unable to conduct surveillance.

We raise this bit of recent history because it typifies the disingenuous way in which this debate has been conducted. While making unfounded claims in public, defenders of the status quo have twisted the rules in private to stiff-arm any meaningful debate on common-sense reforms.

When Congress returns after the August recess, we hope that leadership in the House and Senate will respect regular order and allow for a meaningful debate of the kind that they were unafraid to permit in past Section 702 debates. Members of Congress should be allowed to vote on:

  • Setting the next reauthorization at the latest at or before mid-2028, so Members of Congress can gauge how AI is supercharging surveillance of the American people and reforms can be debated before the next presidential election.
 
  • A warrant requirement before the FBI and other agencies can access Americans’ private Section 702 communications.
 
  • A warrant requirement before federal agencies can purchase and access some of our most intimate information sold to the government by shady third-party data brokers.
 
  • Curbing the “Make Everyone a Spy” provision that obligates most businesses and even houses of worship that provide free Wi-Fi and other communications services to spy on their customers and congregants.

All proposals put forward by reformers contain reasonable exceptions for emergency circumstances.

When Congress returns, won’t it be time, after all the turmoil and gamesmanship of the spring, to finally have a candid debate on these reforms, followed by an up-and-down vote?

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Will Sam Tunick Be Charged as a Terrorist for Erasing His Own Data?

8/22/2026

 

“The Government Doesn’t Own Our Data”

Picture
PPSA has been following the case of Samuel Tunick, who was pulled aside during a customs search at Hartsfield-Jackson Atlanta International Airport in January.

As we’ve often reported, Customs and Border Protection agents have been detaining travelers arriving from abroad until they agree to hand over their phones and other digital devices to search for potentially illegal content.

It is a well-established principle that customs agents can search international travelers’ suitcases for illegal narcotics, weapons, and other contraband. The relatively new practice of scanning digital devices is different, since these devices contain, as a landmark U.S. Supreme Court opinion put it, “the privacies of life.” Such privacies include our stored photos, text messages, and emails, along with any political, religious, or cultural items we download, from books to movies.

It is unknown why Tunick was pulled aside for close inspection. He is a 30-year-old left-wing activist who protested against a large police and fire training center being built in Atlanta. When detained while returning from a vacation in the Dominican Republic, Tunick was asked to give agents the passcode to his phone. He gave them a number that activated his operating system, GrapheneOS, prompting it to delete all the data on his phone.

Tunick was arrested and charged with obstructing federal law enforcement. The question now is whether he will also be charged with “terrorism.” Under National Security Presidential Memorandum 7 (NSPM-7), federal authorities are directed to investigate obstruction of law enforcement at the border as possible terrorism.

On Friday, a New York Times interview with Tunick crystallized much of what we have been saying about these digital border searches. What Tunick said could have come from the mouth of any constitutional conservative or libertarian.

Sam Tunick said:

“If someone you don’t know, who’s actively hostile to you, is trying to access your private data, your pictures, your messages, or notes to self, that may not be something that you’d like …

“. . . it’s interesting to me that my charges and the other federal charges come on the heels of NSPM-7, which is the Trump Administration’s mandate to attack left-wing movements under the bogus pretense of domestic terrorism. I think we should just call that what it is, which is a direct attack on our First Amendment rights to free speech and free assembly.”

To be fair, there have been high-profile instances of people interfering with border enforcement by throwing objects at agents and assaulting them. Whatever you think of the possible expansion of charges to define such people as “terrorists,” does it follow that the erasure of one’s private information should put an American in the same category as Osama bin Laden?

Tunick said that under the charge of obstructing a federal law enforcement agent alone, he could face five years in prison. A traveling musician, Tunick must get the approval of a judge every time he leaves the Northern District of Georgia. Yet he remains defiant:

“Just the knowledge that the government is peering into your private life in this way, trying to dig up dirt on you, even though it’s unsuccessful, it’s creepy …

“I just hope to send the message that the government doesn’t own our data. The government doesn’t own our communications, our relationships, as hard as they might try to.”

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Are Flock Reforms Enough? The Greatest Threat to Privacy Remains

8/21/2026

 
Picture
​Cities and counties across America are “deflocking” – curbing or removing Flock Safety’s automated license-plate readers (ALPRs), with many citizens seeing this technology as a pervasive threat to their privacy.
 
By our unofficial count, almost 50 cities and counties have either terminated their Flock contracts or failed to renew them since 2024. We counted six each in Arizona and California, four each in Washington State and Wisconsin, three in Texas, and many more in 13 other states. Community leaders from coast to coast who are taking these actions are all more or less saying the same thing.
 
“We’ve made clear that we believe Flock systems pose an unacceptable risk to the liberty and privacy of our constituents,” Mike Siegel, a city councilman in Austin, Texas, told KUT News.
 
Flock Safety, backed by $1 billion in venture capital, is clearly reeling from a trend that grew from a squeak of protest into a roar. This is especially true as stories emerge around the country about the misuse of Flock technology by individual police officers for stalking and by Flock personnel for creepy surveillance.
 
Flock is responding. CEO Garrett Langley recently acknowledged and apologized for these shortcomings and announced several operational changes in response.
 
The most salient example is Flock’s reduction of its standard data retention period from a month to seven days. The ACLU, in a sharp but fair analysis of Flock’s changes, conceded that this “may be a step in the right direction.”
 
“Whether this is a real change or just another Flock PR move, however, will depend on how its ‘Evidence Mode’ operates,” the ACLU says. Evidence Mode is a feature that allows law enforcement to preserve specific vehicle and license plate data for ongoing criminal investigations.
 
The ACLU writes:
 
“If ‘Evidence Mode’ only retains hit result data that police determine may be evidence in an active investigation of a specific case, then the change may be a positive one. But if ‘Evidence Mode’ triggers the retention of any ALPR data that is searched, then the new mode could indefinitely retain all of the ALPR data Flock collects and shares nationally.”
 
The ACLU also raised critical questions about Flock’s plans to give communities more control over how their data can be accessed by police in other communities, as well as about the effectiveness of new tools designed to reduce misuse of Flock technology by individual officers.
 
At the same time, it would be a disservice to overlook Flock’s usefulness.
In a recent interview with Detroit’s Local 4 reporter Lauren Kostiuk, Langley quoted a Florida sheriff who speculated that the recent national decline in crime might well be attributable to Flock’s never-blinking eye. Langley credited Flock with helping find than 1,000 missing people and identify 22,000 stolen cars across the United States in one month.
 
Charles Fain Lehman of the Manhattan Institute made similar points in a piece in The Atlantic, “In Defense of Flock.” He wrote that the certainty of apprehension is a powerful disincentive to commit a crime – and that the more surveillance there is, the less crime there will be.
 
Mike Fox, a legal fellow at the Cato Institute, has a trenchant response.
 
“To test Lehman’s thesis, one need only apply his logic to his own doorstep. Imagine if the local police department installed a high-resolution pole camera directed squarely at his front door. By his own logic, Lehman should be elated: The camera would deter prospective burglars and, should an intruder ignore it, capture their every movement in crisp detail to ensure swift apprehension.
 
“Naturally, this arrangement requires government officials to observe every detail of Lehman’s private life. With sufficient resolution, operators could log the packages delivered to his porch, track his every departure and return, note when he walks his dog, and monitor when his children leave for school. Under Lehman’s framework, none of this should disturb him; it is simply the price of crime suppression. His home might never be burglarized, but the cost is continuous state surveillance of his castle.”
 
Even a search of Lehman’s doorstep limited to seven days would be deeply intrusive.
 
Some critics see Flock as an exemplar of surveillance capitalism, although Flock does not own or sell the data its technology generates. (Law enforcement customers own the data.) PPSA has a broader concern, one illustrated by Mike Fox’s thought experiment scaled up to a national system of 120,000 Flock cameras across 49 states.
 
Whatever Flock’s policies and safeguards, our nation is building out a network that could be used by the government to track anyone throughout their daily life. While there is no federal portal into Flock, tracking data in the hands of local law enforcement and perhaps regional “fusion centers” could wend its way upward to politically influenced agencies in Washington, D.C.
 
The greatest danger is that such data could fall into the hands of officials and agencies eager to create dossiers on Americans by tracking our political, business, romantic, and religious associations. In short, Flock could take us down the road to a Russian or Chinese-style surveillance state.
 
That danger is all the more reason for Congress to step in and prevent such an evolution by subjecting the use of data generated by ALPRs to safeguards grounded in the First and Fourth Amendments.
 
Congress should consider requiring warrants before ALPR data may be used to track individual Americans. Congress should also explicitly ban the use of Flock data to monitor how Americans exercise their speech and associational rights in politics, religion, and other sensitive areas.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Supreme Court’s Chatrie Opinion Is a “Blockbuster” that Will Subject High-Tech Spying Systems to New Standards and Scrutiny

8/18/2026

 
Picture
​Six weeks after the U.S. Supreme Court’s 6-3 opinion in Chatrie v. United States, it is just now becoming clear what a breakthrough opinion it actually was.

This ruling leaves an altered legal landscape, one in which courts have fresh opportunities to apply stringent constitutional scrutiny to many intrusive technologies, ranging from automated license plate readers to internet search histories.

At first, this ruling struck many legal observers as a welcome but modest expansion of Fourth Amendment law. Basing its conclusions on recent precedents, the Court held that whenever the government uses a geofence warrant to pinpoint an individual’s location history through cellphone data, it is performing a Fourth Amendment search.

Stanford Law School professor Orin Kerr has now written a sharp analysis contending that Chatrie’s apparently narrow ruling is, in fact, a “blockbuster” that offers the most “rhetorically broad vision of the Fourth Amendment” in 140 years. We think he is right.

Kerr writes that Chatrie “is an expansive pro-privacy opinion that advances new principles and throws into question a wide range of existing surveillance practices.”

The Principle of Consumer Perception

Much of Chatrie’s majority opinion was grounded in precedent, such as Carpenter v. United States. This 2018 ruling held that a warrant is required to track a person’s location history, while limiting that standard to location data collected from cell towers.

“But a close look shows that Chatrie recasts precedents at every turn,” Kerr writes. “Chatrie alters the applicable approaches, adopts new standards, and drops old distinctions.”

For example, a generation ago, the Fourth Amendment was widely understood to prohibit authorities from searching property and “effects” inside a home, a car trunk, or a suspect’s pockets without a warrant based on probable cause. Outside those protected spaces, authorities were – and are – generally free to tail people or rifle through their garbage.

Chatrie demolished this inside/outside distinction. Data held in the cloud can now enjoy a level of protection similar to that of a document in a desk in one’s home. Another way Chatrie goes beyond Carpenter is by bringing users’ perceptions into the equation. Kerr writes:

“It appears that a typical user’s perception of connection with data – generally a matter of app design and interface – can govern whether there are Fourth Amendment rights in the data after the data is disclosed.”

The Intimacy of Data as a Factor
​

Kerr notes that the ruling introduces new concepts into Fourth Amendment law, holding that data generated by ordinary activities on cellphones cannot be presumed to be voluntarily disclosed to third-party tech companies. And Chatrie reorients Fourth Amendment law around the intimacy of private information, rather than the manner in which it was obtained.

Kerr quotes Justice Sonia Sotomayor’s concurrence in a prior case, in which she noted that GPS records contain a “comprehensive record of a person’s public movements that reflects a wealth of detail about her familial, political, professional, religious, and sexual associations.”

This reasoning from one justice in a 2012 case about GPS seems to have filtered into the majority’s thinking about technology in general.

What’s Next?

Where does the law go from here? Some courts will undoubtedly interpret Chatrie narrowly, restricting it to location data. Doing so, however, would ignore the broader implications of Justice Kagan’s majority opinion and its new standards.

We can expect conflicting rulings as lower courts try to apply Chatrie to automated license plate readers, tower dumps, IP addresses, subscriber information, internet search terms, blockchain transactions, and online undercover operations.
​

If lower courts are true to Chatrie, they will recognize a constitutional imperative to apply the Fourth Amendment to curb the unprecedented power of new technology to expose the entirety of a human life. 

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Why Did the SEC Track Americans’ Air Travel Without a Warrant?

8/17/2026

 
Picture
The Securities and Exchange Commission is charged with policing securities markets. It is not an intelligence agency. So why was it secretly monitoring the air travel of people under investigation?

Collin Mercer of Tech Times reports that newly released documents show the SEC purchased access to the Travel Intelligence Program, a massive airline-ticket database maintained by the Airlines Reporting Corporation (ARC).

ARC is a clearinghouse that processes transactions between airlines and travel agencies. This gives it access to passenger names, credit card numbers, flight numbers, travel dates, and departure and arrival cities. Its database contained more than one billion records, including information about flights between foreign countries.

The SEC did not merely search historical records. It subscribed to a surveillance service that automatically compared new bookings against the agency’s watchlists. Whenever a listed individual purchased a ticket, the SEC could receive an alert within 24 hours. The agency requested the ability to receive between one and 25 such alerts a day.

No warrant was required, nor did a judge review whether the surveillance was justified.

The SEC may have used this information to investigate insider trading or determine whether two people suspected of exchanging confidential information had traveled to the same place. This form of tracking could have provided complementary evidence in cases flagged by ARTEMIS, the SEC’s data analytics platform that sifts through six billion trading records to identify transactions that have the hallmarks of insider trading.

But a plausible investigative purpose does not erase the Fourth Amendment. If the government wants to track someone’s movements, it should demonstrate probable cause to a judge.

As PPSA has reported, ARC’s government customers have also included Customs and Border Protection, the Bureau of Alcohol, Tobacco, Firearms and Explosives, the Transportation Security Administration, the State Department, the U.S. Marshals Service, and the IRS. The SEC’s participation demonstrates the limitless nature of the data-broker loophole: If one federal agency can purchase sensitive information without judicial review, virtually any agency can.

ARC ended the Travel Intelligence Program in 2025 after its surveillance activities attracted public and congressional scrutiny. But the legal loophole that enabled the program remains open, and other vendors can offer similar services.

Nor does the end of TIP mean that suspects will be informed that they were targeted. Since the SEC brings civil enforcement actions, rather than criminal prosecutions, it is not obligated to turn over exculpatory evidence to the people it charges the way prosecutors must. So people whose travel was tracked by the SEC while TIP was in play may never learn that their personal data was used to bring a case against them.

The SEC should fill in the blanks by disclosing how it used ARC’s information, whether that data remains in government systems, and whether it has purchased comparable information from other brokers. It should then formally renounce this practice.

While this SEC practice appears to have been curbed, at least a dozen other federal agencies – including the FBI, the IRS, the Department of Homeland Security, and the Pentagon – are still purchasing Americans’ digital data, including search histories and communications metadata, from shady third-party data brokers for unknown uses.
​

Congress should investigate and inform the American people about how our government uses and abuses our purchased data.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

The Elements of a Surveillance State – Capabilities Plus Intent

8/10/2026

 
Picture
An unsecured police database has provided a rare glimpse inside China’s surveillance state.
 
The database examined by The New York Times tracked hundreds of foreigners. But its significance extends far beyond the surveillance of foreign residents. As The Times reports, its existence illustrates how Chinese authorities aggregate vast amounts of information from surveillance cameras, medical records, utility bills, facial-recognition systems, and other sources to monitor and analyze individuals’ behavior.
 
The database included hospital visits, gas payments, frequently visited locations, and air and rail travel – down to seat numbers. It tracked one woman’s movements from her home to shopping malls, restaurants, and supermarkets, sometimes using facial recognition.
 
The power of China’s surveillance system does not rest on any single camera or database. It comes from joining countless streams of personal information into one comprehensive picture.
 
Now for the turnabout: Is the United States a surveillance state like China – or are we about to become one?
 
Consider recent reports on the domestic surveillance capabilities our government already possesses:
 
• Foreign communications: Section 702 of the Foreign Intelligence Surveillance Act, now awaiting congressional reauthorization, allows federal agencies to collect global communications. That collection inevitably sweeps in Americans’ messages, which the FBI has searched millions of times in recent years. Congress must debate a warrant requirement before federal agencies are allowed to search Section 702 data for Americans’ communications.
 
• Forcing businesses to spy on their customers: The “Make Everyone a Spy” provision of the most recent FISA reauthorization in 2024 dramatically expanded the definition of an electronic communications service provider. It can require owners and operators of commercial facilities and even churches housing communications equipment (including common services like free WiFi) to assist government surveillance – and remain silent forever under a gag order.
 
• Political and social-media activity: The Wall Street Journal reports that ICE has established a round-the-clock dragnet across Facebook, Instagram, X, and other platforms. Contractors prepare dossiers that can include a person’s name, address, workplace, Social Security number, vehicle registration, and criminal history. DHS has reportedly issued hundreds of subpoenas to identify anonymous critics, while agents have confronted Americans over online speech.
 
• DNA: According to Wired, ICE may have contributed almost 920,000 DNA profiles to the FBI’s CODIS database in 2025 alone. The broader DHS collection program includes people accused of no crime. Newly released CBP records show that it has even collected DNA from children as young as four.
 
• Air travel: The Securities and Exchange Commission purchased access to more than one billion airline-ticketing records, according to 404 Media. These records covered not only domestic U.S. flights and international flights involving the United States, but also travel between foreign countries. The airline-owned data broker reportedly made this information available without passengers’ knowledge and likely without warrants.
 
• Movements on the ground: Flock Safety cameras record millions of drivers in thousands of American communities. Flock has announced plans to combine license-plate-reader records with public records, open-source intelligence, and commercial “people lookup” data. This can transform a vehicle sighting into a dossier – and allow algorithms to generate suspicion from ordinary patterns of movement.
 
So, is the United States a surveillance state?
 
In terms of capabilities, yes.
 
In terms of intent, not quite – at least not yet at the comprehensive, integrated scale practiced by China.
 
It would take a concerted effort to bring all these elements together into a single system – integrated by artificial intelligence – to comprehensively surveil Americans through their faces, foreign communications, DNA, geolocation, movements, searches, and interests.
 
In short, what separates the United States from Chinese levels of comprehensive surveillance is not capability. It is the intent of government officials – and our trust that they will respect the institutional and constitutional restraints that stand in their way.
 
And in case you have been living off the grid in the Australian Outback for the last decade, trust is in short supply these days.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Part I: Flock’s Cameras Were Supposed to Watch for Criminals – Why Were Employees Watching Children?

8/5/2026

 
Picture
Automated license plate readers are sold to communities as straightforward public-safety tools: cameras photograph passing vehicles, record their license plates, and alert police when they detect a car linked to a crime.

But Flock Safety is becoming much more than a network of license plate readers. As the company integrates traffic cameras, police databases, drones, and privately owned video feeds into a surveillance platform, the opportunities for abuse are multiplying.

Mary Rooke of The Daily Caller highlights a disturbing example from Dunwoody, Georgia. Local resident Jason Hunyar used public-records requests to obtain audit logs showing how Flock employees accessed cameras connected to the Dunwoody Police Department’s surveillance system. Some of those cameras were inside the Marcus Jewish Community Center of Atlanta. They showed swimming pools, fitness studios, preschool hallways, and gymnastics rooms where children practiced in their leotards.

Hunyar found that one Flock executive had accessed Dunwoody’s live and recorded footage 185 times since the beginning of 2025. On one occasion, the only camera he viewed was inside the gymnastics room. Another Flock employee clicked through several cameras at the community center before settling on a view of its main pool.

Why were employees of a surveillance vendor looking at these feeds? Why did sales and business-development personnel have such access in the first place?

We should not rule out an innocent explanation. But even if there is one, this story demonstrates the many ways these camera systems can be misused in ways to threaten Americans’ privacy.

A camera installed for one purpose can quietly become part of a much larger system. A feed intended to protect a private facility can become available to police officials, corporate employees, outside agencies, or any hacker who defeats the system’s security. License plate records can be combined with video, location histories, and other databases to produce an increasingly intimate picture of people’s lives.

Communities with Flock technology should require enforceable limits on who may access cameras and data, individualized credentials, prompt disclosure of misuse, independent security testing, and meaningful penalties for improper access. Cameras inside private facilities – especially spaces used by children – should never be swept into police surveillance networks without fully informed consent and exceptionally strong protections.
​
The question is no longer simply whether these systems can help police solve crimes. It is whether any claimed benefit justifies building a surveillance network that may enable strangers to watch us and our children.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Part II: Harrisonburg and Other Cities Tell Flock to Fly Away

8/4/2026

 
Picture
Amid mounting concern about the misuse of personal data from Flock Safety cameras, the college community of Harrisonburg, Virginia, has joined the growing ranks of American communities rejecting that company’s pervasive surveillance of motorists.

The Harrisonburg City Council voted unanimously to end the city’s contract with Flock Safety, shut down its automated license plate readers, and cover the cameras with trash bags until they can be removed. The council also adopted a policy encouraging future councils to consider privacy, data security, equity, and public trust before deploying similar technology. Residents are continuing to press for a binding ordinance that would require public scrutiny of any future mass-surveillance proposal.

Harrisonburg Mayor Deanna Reed acknowledged that Flock cameras can help solve crimes. But she concluded that its risks outweighed its benefits.

“We might not share the data, that doesn’t mean that somebody can’t get a hold of what we have,” Reed told a reporter at WHSV, a local television station. “The safest thing to do is just not use it at all.”

That is a sensible response to a technology that does far more than snap an occasional picture. Flock’s artificial-intelligence system records license plates and vehicle characteristics, allowing police to reconstruct a person’s movements and search for vehicles by color, model, dents, and bumper stickers. Networks linked across jurisdictions can transform scattered observations into a detailed account of where someone worships, works, seeks medical treatment, associates with others, or attends a political protest.

Then there is the problem of accuracy.

A Business Insider investigation found that Flock’s software misread plates in 71 percent of the stolen-vehicle and felony alerts it sent to police in Roseville, California, during 2023 and 2024. Records showed that the cameras also produced blurry images, missed vehicles, and sent delayed alerts. Roseville’s unusual camera positioning may have contributed to the errors, and its police said none of the false alerts resulted in a stop or arrest because officers independently verified the information.

Other communities have not been so fortunate. Flock errors, sometimes compounded by failures of police verification, have led innocent drivers elsewhere to be stopped at gunpoint, jailed, and even mauled by a police dog.

Harrisonburg is part of a genuinely bipartisan revolt. Charlottesville ended its Flock pilot program over concerns about data protection, misuse, and local control. In Bandera, Texas, opposition came from residents steeped in a conservative tradition of personal liberty and distrust of government overreach. Across the ideological spectrum, Americans understand that tools to combat serious crimes can easily expand into routine, warrantless monitoring.

Police should use targeted investigative methods to pursue people reasonably suspected of crimes. They should not assemble a searchable record of everyone’s movements just in case someone might later come to the attention of authorities.
​
Harrisonburg has made the right call. Other communities should follow its lead and tell mass surveillance to get the Flock out.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Pegasus Rears Its Head In Morocco: “We Spy on Everyone”

8/4/2026

 
Picture
We’re shocked – shocked! – to find that spying is going on in Morocco. That country’s intelligence service is using what may be the world’s most powerful spyware to target “journalists, human rights defenders, French politicians and Spanish cabinet ministers and police officers,” according to reporting led by Sam Jones for The Guardian.

The new evidence comes from a whistleblower who previously worked for Morocco’s internal security services and was uncovered in a collaborative journalistic investigation that includes Amnesty International’s Security Lab.

The spyware Morocco is believed to have used includes the infamous Pegasus, which allows its operator to access everything on a target’s mobile phone, including emails, text messages, and photographs. This software does not require the victim to fall for a phishing scam, but can simply install itself remotely. Pegasus can also activate the phone’s recorder and camera, turning it into a 24/7 listening and video-recording device. In July, Security Lab published a technical analysis of Pegasus, labeling it “the world’s most notorious spyware system.”

Pegasus manufacturer NSO Group says it sells its software to governments that need help tracking criminals and terrorists. For its part, Morocco denies having any relationship with NSO. The investigation’s leader Forbidden Stories and its partners found evidence to the contrary.

For entities with an interest in such technology, Pegasus is particularly appealing because, again, it can infect phones remotely – physical access no longer required. This spyware also has the added advantage of erasing any evidence of its existence. What used to be exceedingly difficult – traditional field intelligence – has suddenly become easy.

Perhaps too easy. As described in the accompanying documentary, “Pegasus Project: Inside the Moroccan Spying Machine,” after Morocco’s intelligence service realized what it possessed in Pegasus, its agents quickly added the cell numbers of Moroccan journalists and human rights defenders. Not exactly “criminals and terrorists.”

And before long, The Guardian reports, “the targeting had begun to extend beyond Morocco’s borders,” eventually including 200 Spanish mobile numbers, among them those of the prime minister, the minister of defense, the interior minister, and the minister of agriculture. Spain dropped its initial investigation, only to briefly reopen it after French authorities shared details of their own Pegasus experience.

“We spy on everyone,” a former Moroccan intelligence officer said in conversation with the journalists, “just in case.”
​
It’s all just one more chapter in the unfolding real-life thriller that is the NSO/Pegasus drama.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

“Netflix for Stalkers” – How Flock Exposes Americans to Internet Stalkers

7/27/2026

 
Picture
Imagine taking your child to a playground and later learning that strangers could watch her play live online – or replay it at any time.

Technology researcher and YouTuber Benn Jordan discovered an alarming example of privacy vulnerability – a Flock Safety camera permanently aimed at a playground near the San Francisco Bay Area was openly broadcasting over the internet. No username or password was required.

Jordan and security researcher Jon “GainSec” Gaines found nearly 70 unsecured Flock cameras through a commercial search engine that catalogs internet-connected devices. The cameras were so easy to access that Jordan compared the system to “Netflix for stalkers.”

These were not merely license plate readers. They included Flock’s Condor cameras, which can pan, tilt, and zoom – and use artificial intelligence to detect and follow people automatically. Condor is not a license-plate reader. It is a people watcher.

Jordan says he watched a man leave his home in New York and a woman jog alone on a wooded trail in Georgia. He watched a man rollerblade, stop, and view videos on his phone. The camera’s AI zoomed in closely enough to see what he was watching.
​
Jordan also saw a couple arguing at an Atlanta street market – and used common internet resources to identify their health and financial problems. In another disturbing sequence, he observed emergency responders attending to an apparently injured person. All of this was available to anyone who found the feeds.
The exposure went far beyond live viewing. According to 404 Media, visitors could access administrative controls, download about a month of archived footage, change settings, inspect logs, run diagnostics, and even delete video. Jordan demonstrated the vulnerability by standing beneath one of the cameras and watching himself on his phone in real time.

Flock called the episode a “limited misconfiguration” affecting a small number of devices and said it had corrected the problem. But that response misses the larger lesson.

As Jordan stresses later in his account, responsibility also rests with the local governments that purchase and deploy these systems. City councils and police departments are building interconnected networks of AI-enabled cameras without first demanding rigorous independent security audits, enforceable access controls, clear data-retention limits, and public accountability.

Local officials cannot outsource their responsibility to protect citizens’ privacy. Before approving surveillance technology, they should understand precisely what it records, who can access it, how it can be abused, and what happens when its security fails.
​
A camera installed in the name of public safety should not become an unlocked window into a child’s playground, a couple’s argument, or anyone’s daily life.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

More on Mobile Spy Units

7/20/2026

 
Picture
​The story of the mobile spy SUVs purchased by the state of Texas for $4.5 million continues to unfold.

According to Alex Barrientos of Gadget Review, the Texas Department of Public Safety’s purchase of four Chevy Tahoes includes an extra $3.9 million for a proprietary surveillance system from a company named Cognyte, Israel’s version of Palantir. Cognyte is the maker of the FalcoNet surveillance technology embedded in the SUVs.

FalcoNet, writes Andrew Collins of The Drive, has already been deployed in Florida (as has similar stingray technology elsewhere). Its purpose is simple, if ominous: get between cellphone towers and any phones that happen to be near them, and then secretly intercept and capture everything that being transmitted.

FalcoNet and its competitors do this by pretending to be ordinary cell towers, tricking every phone nearby into connecting (smartphones can't help themselves because they are programmed to respond to the strongest signal). Cognyte claims FalcoNet can be activated in under three minutes and can connect with thousands of devices at once as the surveillance vehicles roll through traffic and past pedestrians.

Those intercepts are meant to catch the communications of bad actors being sought by authorities. But the software cannot filter out the private information of bystanders from that of suspects, which means that Texas and Florida are sweeping up the data of everyone who happens to be in the mobile system’s vicinity. The data of thousands of innocent persons can then be sifted through afterward.

This presumes that only law enforcement will do the sifting – and not hackers, data brokers, or hostile state actors. Even so, that is cold comfort given what we know from the actual abuse and potential misuses of similar surveillance systems.

The growing use of stingrays, whether installed on poles in busy parts of town, in mobile police units, or even mounted on drones, underscores the importance of commercial encryption services in protecting our everyday communications. We should be able to enjoy the same level of privacy in our texts and emails that we expect when having a private conversation with a friend.

Equally important, the entire premise of such spy regimes – no matter what the official rationalization – flies in the face of the Fourth Amendment. Designed to protect against the invasive and indiscriminate mass searches of general warrants, the Fourth Amendment offers a simple calculus: probable cause + a court warrant + narrowly defined search criteria.
In their current forms, programs like the aptly named FalcoNet – and it is a net – are functional dragnets, modern-day general warrants that thwart every aspect of the Constitution’s privacy safeguards. Not even outmoded interpretations of the third-party doctrine can (or should) be invoked to save them.

The good news is that we now live in the Chatrie era. In that recent decision, the U.S. Supreme Court clearly articulated a fundamental right to certain forms of digital privacy, specifically regarding location tracking (including geofencing, the whole raison d'être for those shiny new Texas spy SUVs).
​
In short, this practice of roving mass surveillance is ripe for a challenge in court.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Sen. Wyden Calls Out Canada’s Surveillance Bill

7/20/2026

 
Picture
Senator Ron Wyden (D-OR) | PHOTO CREDIT: New America/Flickr
​When PPSA last examined Canada’s proposed Lawful Access Act, we described how it could undermine encryption and endanger privacy worldwide. Now Sen. Ron Wyden (D-OR) is warning that the bill could also enable the Canadian government to conscript American technology companies into spying on Americans.

Bill C-22, which has passed Canada’s House of Commons and is now before the Canadian Senate, would grant authorities in Ottawa sweeping new surveillance powers. It would require service providers to retain sensitive user metadata, such as location information, for up to a year. It could also force companies to alter their systems to facilitate government access or install tracking capabilities and security backdoors. 

In a letter to Secretary of State and acting National Security Adviser Marco Rubio and acting Attorney General Todd Blanche, Sen. Wyden writes that the bill “threatens to weaponize American technology infrastructure by enabling the Canadian government to force U.S. companies to secretly facilitate surveillance of Americans, while systematically undermining the security of their products.”

A foreign government could conceivably pressure an American company to retain special backups of an American target’s data, relocate encryption keys to a jurisdiction where they could be seized, or deliver government spyware through a compromised software update.
The target could be anyone.

As Sen. Wyden warns, “U.S. law does not explicitly prohibit American companies from secretly facilitating foreign surveillance of U.S. citizens – even if the target is the President or another senior U.S. government official.”

“This is not a dilemma of U.S. companies being caught between conflicting international legal obligations,” he writes. “It is a glaring statutory vacuum.” 

Canada is negotiating an agreement with the United States under the CLOUD Act, which would enable Canadian authorities to seek some data directly from American companies. Sen. Wyden urges the Trump Administration to use those negotiations to obtain “ironclad, explicit prohibitions” against Canadian demands that U.S. companies reengineer their products or facilitate surveillance of Americans.

As PPSA has warned, there should be no encryption backdoor reserved for trustworthy governments. Any vulnerability can be exploited by hostile governments, criminals, and increasingly capable artificial intelligence systems.

Sen. Wyden puts the principle succinctly: “Bilateral trust with our closest intelligence partners cannot be built on the secret subversion of American cybersecurity infrastructure.”
​

The Trump administration should heed his warning. Canada must not be permitted to turn American technology companies into instruments of secret spying on Americans.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Why the Struggle for Surveillance Reform Is as American as the Fourth of July

7/4/2026

 

"Custom-house officers may enter our houses, when they please ... may break locks, bars, and everything in their way; whether they break through malice or revenge, no man, no court can inquire."
 
James Otis Jr.

Picture
​Every Fourth of July, Americans happily celebrate the Declaration of Independence as the birthday of our nation. As we grill our feasts in our backyards, however, we should also remember that the Declaration was not a mere flight of rhetoric. It was the culmination of years of growing outrage over arbitrary government power.
 
The first great spark came in 1761, when Boston lawyer James Otis Jr. challenged the British Crown’s use of Writs of Assistance – “general warrants” that allowed customs officials to search homes, businesses, and ships without individualized suspicion.
 
John Adams, then a young lawyer watching Otis argue, never forgot what he heard. He would later say, "Then and there the child Independence was born."
 
The Declaration of Independence would later thus condemn King George III for subjecting Americans to “pretended legislation” and arbitrary rule. The Founders understood that liberty cannot survive when government officials possess unchecked authority to search first and justify later. The Fourth Amendment – requiring a probable cause warrant before government can inspect our persons, houses, papers, and effects – would not be ratified until 1791. But the principles behind the Fourth Amendment’s protections were already growing deep roots long before independence.
 
Today’s government no longer carries paper writs signed by the Crown. And police and the FBI almost always respect the need for warrants to enter homes. But modern technology has created powerful new versions of general warrants. These include:
 
  • Warrantless searches of Americans’ communications collected by federal intelligence agencies from global communications under FISA Section 702.
 
  • Government purchases of Americans' sensitive location, financial, and internet-browsing data from commercial data brokers, sidestepping the warrant process altogether.
 
  • Geofence warrants that compel technology companies to identify everyone whose devices happened to be near a location, treating entire crowds as potential suspects.
 
  • Mass collection of license plate reader data, allowing governments to reconstruct the movements of millions of innocent drivers.
 
  • The “Make Everyone a Spy” provision that obligates most businesses and houses of worship that provide Wi-Fi and internet connections to secretly spy on their customers and congregants for the National Security Agency.
 
We are thus back to Otis’s age of general warrants, only this time instead of Redcoats ransacking our homes, the government uses AI-enabled algorithms probing our smartphones, data in the cloud, and digital records.
 
As Congress prepares to again debate federal surveillance policy, Members would do well to remember James Madison’s admonition: “In framing a government … you must first enable the government to control the governed; and in the next place oblige it to control itself.”
 
Will Congress ensure that our government controls itself by placing guardrails on rampant warrantless federal surveillance of the American people?
 
The Fourth of July should remind us why independence was declared in the first place. The generation that pledged its lives, fortunes, and sacred honor did so in part because it refused to live under a government armed with unchecked surveillance authority.
 
The best way to honor that legacy is not merely to celebrate liberty once a year, but to preserve it every day by ensuring that 21st-century surveillance powers remain subject to the same constitutional restraints the Founders demanded from the very beginning.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

When Big Tech Becomes Your Local Police Department

6/26/2026

 

ACLU details the many ways the mixing of the profit incentive with prosecution can go wrong

Picture
​Imagine if one private company didn't just sell equipment or software to your local police department, but became the operating system for policing itself – managing body camera footage, dispatch records, 911 calls, jail bookings, license plate reader databases, AI analytics, and more, all through a single cloud platform.
 
This dystopian vision, taken to an extreme in the classic film RoboCop – in which a predatory corporation acquires an entire police department – is arriving faster than most Americans realize. The integration of business and policing raises new concerns about privacy, accountability, and the concentration of surveillance power.
 
Vendors are pressing this “operating system” model on police departments, seeking to collect, manage, control, analyze, and optimize the flow of data that contains sensitive information on millions of Americans – including not just suspects, but also their families, neighbors, co-workers, friends, and crime victims.
 
A new white paper released by the American Civil Liberties Union and authored by Jay Stanley with Lauren Yu details all the reasons why the integration of corporate and police priorities can degrade the traditional constitutional protections built into policing.
 
Weak protections for AI-derived data
Stanley and Yu note that with so much collected data, “vendors are pushing AI hard on their law enforcement customers as a shortcut to squeezing value out of data. Examples include video analytics, AI-assisted police reports, and algorithmic inspection of license plate reader data for ‘suspicious’ movement patterns.”
 
What uses might this valuable data serve beyond law enforcement? Many companies pledge not to share, sell, or access data except in tightly controlled, audited circumstances for support and maintenance. 
 
Stanley and Yu write: “The problem is the lack of barriers to violating these promises and the near impossibility of discovering if those clauses are violated because of how easy it is to copy, transfer, and share data without leaving any fingerprints, especially within an opaque private company.”
 
Lack of checks and balances
 
Law enforcement answers to democratically elected officials. Transparency and accountability are enforced by Freedom of Information Act (FOIA) requests, email and other data retention requirements, and the budgetary and policy oversight of city councils, oversight boards, internal affairs bureaus, and other officials.
 
Companies lack these checks and balances. Local governments are learning to offload responsibilities to the private sector to shield themselves from public scrutiny. In New Orleans, for example, the police avoid local regulations on facial recognition by using a private organization to apply that technology on their behalf.
 
And when something goes wrong, the authors note, “you can’t use voter pressure to make a bad company ‘resign’ the way a sheriff might do if they do something bad.”
 
Bias toward prosecution
 
The mixture of profit and prosecution could degrade traditional safeguards in police work. Stanley and Yu write:
 
“Vendors in the law enforcement space have an incentive to demonstrate that their products are great at helping police catch criminals. This means that they have a financial incentive in being able to say that their products led to a high number of arrests and convictions – they gain no marketing advantage when crime is low and people go free.”
 
Vulnerable honeypots
 
For decades, police records tended to remain scattered among thousands of local departments. But cloud computing changes that equation. Information that once sat on local servers is increasingly stored in centralized corporate systems, creating nationwide repositories of highly sensitive data.
 
With so many companies centralizing and storing police data in the cloud, vendors are creating “honeypots” of sensitive data attractive to hackers. “Worsening the situation is the fact that good cybersecurity costs money, and yet most costs of breaches often fall not on the company but on ordinary people.”
 
As surveillance technologies become more powerful and more interconnected, policymakers should ensure that constitutional protections evolve just as quickly. Otherwise, the greatest expansion of police surveillance may come from corporations quietly becoming policing’s digital backbone, if not its brain.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

School Buses as Mobile Surveillance Units: How Child Safety Concerns Can Be Hijacked to Build a “Hellscape of Surveillance”

6/2/2026

 
Picture
​When you hear of a new surveillance program being marketed as a child-safety initiative, give it particularly close scrutiny. History shows that the narrower and more compelling the stated justification for a surveillance plan, the broader and more outlandish the surveillance will actually be.

A newly reported example comes from BusPatrol, a company that has installed AI-powered camera systems on more than 40,000 school buses in 24 states. The cameras have been marketed as a way to identify drivers who ignore the fold-out “STOP” arm signs from buses and illegally pass them while stopped. 

Joseph Cox of 404 Media reports that BusPatrol is now planning a dramatic expansion of its mission. Leaked company documents reportedly show plans to convert school buses into roaming automatic license plate reader (ALPR) platforms that would capture information on every vehicle a bus passes, regardless of whether any crime or traffic violation occurred. The resulting data would then be sold to law enforcement. 

A system designed to document a specific violation at a specific moment is fundamentally different from a system that continuously records the movements of everyone nearby. In effect, school buses would become mobile surveillance vehicles.

Under the proposal, cameras would photograph vehicles, record their license plate numbers, and attach GPS location data. Law enforcement and possibly other actors could then query those records to reconstruct a vehicle's travel history. As privacy advocates have long warned, tracking a car often means tracking a person. 

These bait-and-switch tactics are familiar.

After the attacks of September 11, Americans were told that extraordinary surveillance programs were necessary to prevent terrorism. Many of those authorities later expanded far beyond their original scope. Section 702 of FISA was enacted to monitor foreign threats overseas, yet the communications of millions of Americans became subject to warrantless searches.

From the UK to Congress, we’ve seen how the fight against child sexual abuse material has been used as a shield to threaten the encryption that protects women and children from stalkers, journalists from vengeful politicians, businesses communicating about proprietary information, and millions of law-abiding Americans who want to have a digital conversation without Big Brother listening in.

Government agencies have repeatedly justified the acquisition of vast quantities of personal data by pointing to legitimate public concerns, only for those powers to evolve into broader surveillance tools.

BusPatrol's reported plans follow the same trajectory. A narrowly tailored safety program aimed at preventing children from being struck by passing vehicles could become a platform for collecting location information on millions of ordinary Americans who have done nothing wrong.

The danger is not merely the collection of data. It is the normalization of surveillance infrastructure. Every new camera network creates pressure to find new uses for the information it gathers. Indeed, BusPatrol’s internal documents suggest that this latest move is in response to investor demands for new revenue streams.

Protecting children is a worthy goal. Turning school buses into rolling location-tracking platforms is not.
​
Americans should be wary whenever government agencies or private contractors ask them to trade away privacy in exchange for safety. Proposals like this need their own mounted “STOP” arm signs.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Why Is the Administration Withholding a Secret Court Opinion on Violations of Americans’ Constitutional Rights During a Surveillance Debate?

5/29/2026

 

Will Tulsi Gabbard Release the Report Before She Leaves Office?

Picture
ODNI Director Tulsi Gabbard. Photo Credit: Gage Skidmore
​Tulsi Gabbard is set to depart her post as Director of National Intelligence on June 30 to care for her ailing husband. Before she leaves, Director Gabbard has a golden opportunity to advance government transparency by releasing a secret opinion of the Foreign Intelligence Surveillance Court (FISC) detailing what Sen. Ron Wyden (D-OR) has described as “violations of Americans’ constitutional rights” involving Section 702 of the Foreign Intelligence Surveillance Act (FISA).
 
Inexplicably, the Justice Department notified Congress in April that it is appealing the release of this crucial opinion describing how the FBI and other agencies violated laws or procedures governing Section 702. Congress enacted this authority to facilitate the surveillance of foreign threats abroad, but in recent years the FBI has also used it to gain warrantless access to the communications of millions of Americans.
 
On May 1, Sen. Wyden secured commitments from the bipartisan leaders of the Senate Intelligence Committee – Sen. Tom Cotton (R-AR) and Sen. Mark Warner (D-VA) – to declassify this important opinion detailing how the FBI and other agencies violated laws and procedures regulating Section 702.
 
Yet the Trump administration continues to block the release of this information in the midst of an intense surveillance debate, as Congress has struggled for weeks to reauthorize Section 702. Releasing the opinion would help lawmakers determine whether the FBI is still conducting warrantless “backdoor” searches of Americans’ communications despite the guardrails Congress enacted during the 2024 reauthorization.
 
What might kinds of violations may have occurred?
 
Liza Goitein of the Brennan Center for Justice reports that the FBI used an “advanced filtering function” to “search for U.S. persons’ communications using terms associated with those persons.” Although such searches plainly met the statutory definition of a query, “the FBI did not treat the searches as queries and therefore did not track or count them.”
 
The existence of a querying tool that allegedly operated outside statutory constraints raises broader concerns. If one such tool escaped oversight, could similar tools exist at other agencies – or elsewhere within the FBI – that have not yet been detected by internal auditors or disclosed to Congress?
 
Charlie Savage of The New York Times has reported that a source told him a digital filtering system designed to help analysts refine query results focused on foreigners was also generating results that the secret court deemed warrantless “queries” of Americans’ communications.
 
Beyond confirming these reports, the administration should answer questions, starting with:
 
  • How often did these improper queries occur?
 
  • How many Americans were affected?
 
  • Did the FBI or any other federal agency review the contents of communications obtained through these searches?
 
  • Has any American faced legal action based on evidence derived from such warrantless queries?
 
The Justice Department’s resistance is particularly troubling because it defies the public requests of both the chairman and ranking member of the Senate Intelligence Committee to release this information. At the same time, the administration and House Speaker Mike Johnson have resisted votes on reform amendments while pushing to reauthorize Section 702 without meaningful additional safeguards.
 
Withholding this information from Congress and the American people during an active reauthorization debate displays a troubling disregard for the transparency and oversight a democracy requires.
 
During her confirmation hearing, Tulsi Gabbard pledged to restore trust in the intelligence community through greater transparency and accountability. This is her opportunity to fulfill that promise. Doing so may displease some within the intelligence establishment, but it would demonstrate a commitment to the principles she pledged to uphold – and ensure that her tenure concludes with an act of meaningful transparency.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Check Out FisaReform.org to Learn About Your Stake in the Ongoing Surveillance Debate in Washington

5/26/2026

 
Picture
Screenshot of http://www.fisareform.org/
​Would you like to know what you have at stake in the current congressional debate over the reauthorization of Section 702 of the Foreign Intelligence Surveillance Act (FISA)?
 
Do you want to understand exactly how federal agencies sidestep the U.S. Constitution to gain ready access to your communications, search histories, and data about your finances, health, romantic life, and location histories – including who you meet with, what you believe, where you go?
 
Are you looking for the plain truth about rampant government surveillance beneath Washington’s sea of acronyms?
 
Visit our new Surveillance Coalition website – fisareform.org.
 
On this site you will find a clear description of the issue, what is at stake, and the precise reforms needed.
 
Under the “Section 702 Basics” tab you will find an “Explainer” produced by the Brennan Center for Justice at New York University School of Law that answers these questions:

  • What Is Section 702?
 
  • Whose communications does the government collect under Section 702
 
  • How does the government use Section 702 as a domestic spying tool?
 
  • Are backdoor searches constitutional?
 
  • How have intelligence agencies abused backdoor searches?
 
  • Did Congress fix the problems with Section 702 when it last reauthorized the law?
 
  • How do the current administration’s actions impact concerns about backdoor searches?
 
  • What can be done to protect Americans from warrantless government spying?
 
  • Would a warrant requirement harm national security?
 
  • What happens if Congress doesn’t reauthorize Section 702 by the deadline?
 
Under the “Resources” tab you can read incisive op-eds by leading Members of Congress and our Coalition leaders, including PPSA’s own Bob Goodlatte, in publications ranging from The New York Times and The Washington Post to The Hill – as well as our Coalition letters to Congress and the Trump administration that spell out key reforms needed to protect Americans’ privacy.
 
Finally, under the “National Security Protected” tab you can find a rebuttal to those who say that delaying the reauthorization of the FISA Section 702 surveillance authority – or placing any guardrails on government surveillance of the American people – would be dangerous to our safety.
 
We show step by step how these scaremongering claims are false – how our reforms are carefully designed to protect national security – and why the protection of the homeland can go hand-in-hand with respect for the Constitution and Americans’ privacy.
 
At the entrance of the Central Intelligence Agency headquarters is an engraved inscription from the Bible: “And ye shall know the truth and the truth shall set you free.”
 
We believe that this is good advice for the American people as well.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

What a Small Texas Town’s Rebellion Against Surveillance Tells Us About the National Appeal of Surveillance Reform

5/25/2026

 
Picture
​We don’t condone vandalism. But we have to admit that a recent event in the Texas Hill Country town of Bandera showed a flash of the spirit of the Boston Tea Party, or, perhaps more appropriately, of the settlers in the East Texas town of Gonzales who, in 1835, cried “Come and Take It!” while firing their small brass cannon at the Mexican Army.

We’re talking about the repeated efforts of the Bandera city council to install eight AI-enhanced license plate readers on poles around the town, only to have local residents use saws to cut the poles in half and take down the cameras. After several rounds of this rebellion, the city council finally gave up and ended its contract with Flock Safety, a company that is building a national network of cameras that track cars and store the daily movements of millions of Americans.

Brian McManus chronicles this contest of wills in Courier Texas.

“Bandera is the cowboy capital of the world,” one resident told McManus. “We don’t need to implement mass government surveillance in our town.”

McManus reports that Bandera has a lower crime rate than both the Texas and national averages. Banderans just didn’t like the idea of “ordinary people going about their ordinary lives in a town where everybody already knows everybody.”

There is one aspect of this story that touches on something of national significance. McManus writes:

“This was not a left-versus-right argument. It was rooted in community and the instinct toward personal liberty and suspicion of government overreach that defines much of rural Texas political identity. The irony that a surveillance state program backed by Republican state grant money ran headlong into Republican small-town resistance was not lost on people in the [city council] room.”

While Congress debates surveillance policy, it is clear that national concern about the need to protect the privacy and constitutional rights of the American people cuts across party and ideological lines.

Advocacy for reform amendments to FISA Section 702 comes from Rep. Andy Biggs (R-AZ) and Rep. Zoe Lofgren (D-CA), as well as Sen. Mike Lee (R-UT) and Sen. Ron Wyden (D-OR). Can you think of any other issue that unites staunch conservatives and stalwart liberals?

All of them and many more are backing measures to keep the government’s hands off Americans’ personal data without warrants, as the Constitution requires.
​
They might agree with one Bandera resident who told McManus that surveillance “just doesn’t pass the vibe check.” Neither does the federal government’s warrantless collection and inspection of Americans’ personal data.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS
<<Previous

    Categories

    All
    2022 Year In Review
    2023 Year In Review
    2024 Year In Review
    2025 Year In Review
    Analysis
    Artificial Intelligence (AI)
    Biometric Data
    Call To Action
    Congress
    Congressional Hearings
    Congressional Unmasking
    Court Appeals
    Court Hearings
    Court Rulings
    Data Privacy
    Digital Privacy
    Domestic Surveillance
    Due Process
    Facial Recognition
    FISA
    FISA Reform
    FOIA Requests
    Foreign Surveillance
    Fourth Amendment
    Fourth Amendment Is Not For Sale Act
    Government Surveillance
    Government Surveillance Reform Act (GSRA)
    Insights
    In The Media
    Lawsuits
    Legal
    Legislation
    Letters To Congress
    NDO Fairness Act
    News
    Opinion
    Podcast
    PPSA Amicus Briefs
    Private Data Brokers
    Protect Liberty Act (PLEWSA)
    Saving Privacy Act
    SCOTUS
    SCOTUS Rulings
    Section 702
    Spyware
    Stingrays
    Surveillance Issues
    Surveillance Technology
    The GSRA
    The SAFE Act
    The White House
    Warrantless Searches
    Watching The Watchers

    RSS Feed

FOLLOW PPSA: 
© COPYRIGHT 2026. ALL RIGHTS RESERVED. | PRIVACY STATEMENT
Photo from coffee-rank