Project for Privacy and Surveillance Accountability (PPSA)
  • TAKE ACTION
    • Section 702 Reform
    • PRESS Act
    • DONATE
  • Issues
  • Solutions
  • SCORECARD
    • Congressional Scorecard Rubric
  • News
  • About
  • TAKE ACTION
    • Section 702 Reform
    • PRESS Act
    • DONATE
  • Issues
  • Solutions
  • SCORECARD
    • Congressional Scorecard Rubric
  • News
  • About

 NEWS & UPDATES

Former Police Chief Proposes Guardrails for Flock – Are They Enough?

9/14/2026

 
Picture
Flock Safety cameras and other automated license-plate reader (ALPR) systems have become a national flashpoint in debates over surveillance, policing, and privacy. Even data centers poll better than Flock cameras.
 
Now a former police chief is proposing a detailed framework intended to preserve the investigative uses of Flock and other ALPR systems while imposing new rules governing how police departments operate them.
 
Tom Weitzel, who served as police chief in Riverside, Illinois, has released a position paper on automated license plate reader systems, including the cameras made by Flock Safety. Weitzel, a 37-year law-enforcement veteran, writes that he has seen technology improve policing – and seen its misuse damage public trust.
 
In a letter published by Patch, Weitzel explains what prompted his proposal:
 
“I keep watching the debate and feel stuck between two bad options: leave these systems running with no real oversight or rip them out altogether. I don’t accept either option. I’ve seen ALPR data recover stolen vehicles, locate missing people, and crack violent crime cases that otherwise would have gone cold. Walking away from that capability doesn’t make anyone safer.
 
“At the same time, I won’t defend a system that can’t demonstrate it’s being used honestly.”
 
Weitzel proposes that communities adopt:
​
  • An independent civilian oversight board with subpoena power
 
  • Mandatory written justification and case numbers for every search
 
  • Immutable audit logs
 
  • A 30-day retention limit for data that does not produce a “hit” on an investigative “hot list.”
 
  • A public discipline matrix with zero tolerance for personal misuse.
​
We note that Weitzel’s suggested 30-day retention period for “non-hit” data – images of vehicles not related to any law-enforcement hot list – exceeds the 7-day retention period now recommended by Flock CEO Garrett Langley. We would also recommend including an explicit prohibition against tracking individuals solely on the basis of their religious, political, or journalistic activity protected by the First Amendment.
 
His paper also proposes transparency measures, including a dashboard that reports aggregate searches, criminal-activity hits, usage audits, and disciplinary actions against officers. He proposes a public portal called “Explain My Stop,” and the selection of community members by lottery to participate in audits.
 
Weitzel would also institute an annual “State of Surveillance” town hall and independent academic reviews. Other elements include a plain-language explanation of ALPR policies, public accounts of cases solved with ALPR assistance, optional alerts for residents whose plates are searched repeatedly, and independent compliance certification for programs.
 
Weitzel’s framework provides a detailed set of ideas for lawmakers in Congress and state legislatures, police departments, and communities to consider as they debate whether – and under what conditions – to continue using ALPR systems

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Critical Questions for Sen. Hawley to Ask in His Much-Needed Investigation into Flock’s National Surveillance Network

8/31/2026

 
Picture
PICTURED: U.S. Sen. Josh Hawley, R-Mo
Sen. Josh Hawley (R-MO), chairman of the Senate Judiciary Subcommittee on Crime and Counterterrorism, has launched a welcome investigation into Flock Safety’s vast network of automated license plate readers.
 
In a letter to Flock CEO Garrett Langley, Sen. Hawley writes:
 
“In a few short years, Flock has assembled an unprecedented national surveillance network. Your company boasts more than 120,000 cameras across 49 states and more than 20 billion vehicle scans every month. The overwhelming majority of the Americans captured in those records did nothing wrong.”
 
Sen. Hawley adds that, instead of supporting discrete investigations, Flock’s camera data can be harnessed by artificial intelligence “to pool what they capture into a national database that customers can search.”
 
PPSA commends Sen. Hawley for recognizing what a departure from American privacy norms Flock’s technology represents. Flock cameras record the movements of millions of innocent drivers. How that information is collected, stored, searched, shared, and ultimately used should not be governed solely by corporate policies and thousands of customized contracts with police departments scattered across the country.
 
As Sen. Hawley writes:
 
“Americans do not surrender their privacy rights when they drive to work, drop their kids off at school, or go to church. The Supreme Court has recognized that a comprehensive, retrospective record of a person’s movements is different in kind from ordinary observation in public. Congress never authorized the network your industry has built.”
 
The investigation should closely examine how government access to Americans’ movements works – and the potential for that access to evolve into practices we associate with China’s surveillance state. Under Flock’s contracts, state and local police departments generally own the data their cameras generate. How do they use that data?
 
Here are questions for Sen. Hawley and his colleagues to ask:

  • Are federal agencies buying, requesting, or otherwise acquiring that information from state and local law enforcement agencies?

  • Are state-federal “fusion centers” providing another route by which locally collected data enters federal databases or investigations?

  • Beyond Flock Safety’s recommendations, what are the longest periods for which state and local customers are retaining Flock data?
    ​

  • Has any customer ever used Flock data to track political, journalistic, or religious activities protected by the First Amendment?
 
As Sen. Hawley concludes, “the American people want to know who has access to their personal data and how.”
 
Americans deserve to know whether such arrangements allow federal agencies to evade constitutional and statutory safeguards. This investigation should provide those answers – and set the foundation for national standards governing Flock data. At least two safeguards should emerge from this investigation.
 
An explicit prohibition is needed to prevent Flock data from being used to track Americans’ First Amendment activities.
 
Standards should also include strict limits on collection, retention, sharing, and secondary uses, as well as a clear requirement that police obtain a probable-cause warrant before using Flock’s network to track an American’s movements.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Flock Safety CEO Promises “Guardrails” and Vows to Avoid Moving “Recklessly” into “Dangerous” Technologies

8/24/2026

 
Picture
​The threats to personal privacy posed by Flock Safety’s national network of 120,000 automated license plate readers (ALPRs) are generating national pushback. As dozens of communities cancel their contracts with Flock – and Sen. Bernie Sanders (D-VT) calls on Congress to ban Flock – the company’s CEO, Garrett Langley, is undertaking a charm offensive to defend his product by pointing to the technology’s benefits.

In a Saturday interview on Fox News with Kayleigh McEnany, Langley said Flock’s network has helped locate 10,000 missing persons. He claimed that if Flock cameras had been in the right part of Arizona, the disappearance of Nancy Guthrie would not be a mystery.

The Need for Guardrails

Langley said that two priorities must be followed in future regulation. The first priority is to put limits on police departments’ retention of Flock data. Langley said we should all ask, “So how long is this data stored?” Flock now recommends a default retention period of seven days. Langley noted that this is a tighter standard than the 21-day limit imposed by the strictest state legislation.

The second priority, Langley said, is “accountability” for abuses of this technology by a few bad apples in law enforcement.

“Today, it is too often that in Flock and other technologies, there is no regulation. There is no accountability. And we think that’s wrong.”

In response to recent stories about police officers misusing Flock for stalking, Langley pointed to Flock’s change to an “audit assistance tool,” which monitors the ways in which Flock is used.

Flock and AI

McEnany asked Langley about a Wired report on the integration of a powerful new AI tool that allows Flock’s system to use ALPR data and other records to identify drivers (and, by implication, their movements and associations).

Langley acknowledged that AI is “incredibly powerful, but also a very dangerous tool.” He promised not to move “recklessly” into AI. “It requires more third-party attestation; more support from the community.”

Langley added that a consumer might be irritated by an AI agent that flubs a flight reservation. But when one calls 911, he said, “it has to work. There’s no space for hallucinations.”

Langley pledged to seek community support to confirm that AI has appropriate “guardrails.”

Promises Made, But How Will They Be Implemented?

It is a welcome sign that Flock’s CEO acknowledges that his technology needs guardrails and regulation – an implicit admission that its unregulated use poses risks to Americans’ privacy.

It is also a welcome sign that Langley acknowledges that AI is a “dangerous tool” and that it must operate with near-perfect accuracy.

The devil – if not a host of devils – is in the myriad details. For example, the ACLU questions whether Flock’s new audit tool could boomerang and expand surveillance. And the guardrails for AI are, as of today, speculative.

It is not enough to eliminate false positives that could misidentify innocent people as suspects to be targeted by law enforcement. The combination of AI and Flock technology is precisely the kind of tool that enables the surveillance state of the People’s Republic of China.

Congress should consider a law that prohibits federal and state agencies from using AI to search ALPR databases in order to track Americans’ daily movements without a probable-cause warrant.

Otherwise, our daily lives and associations – personal, romantic, political, commercial, and religious – will be an open book.
​
But we should all welcome Langley’s openness to further discussion.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Are Flock Reforms Enough? The Greatest Threat to Privacy Remains

8/21/2026

 
Picture
​Cities and counties across America are “deflocking” – curbing or removing Flock Safety’s automated license-plate readers (ALPRs), with many citizens seeing this technology as a pervasive threat to their privacy.
 
By our unofficial count, almost 50 cities and counties have either terminated their Flock contracts or failed to renew them since 2024. We counted six each in Arizona and California, four each in Washington State and Wisconsin, three in Texas, and many more in 13 other states. Community leaders from coast to coast who are taking these actions are all more or less saying the same thing.
 
“We’ve made clear that we believe Flock systems pose an unacceptable risk to the liberty and privacy of our constituents,” Mike Siegel, a city councilman in Austin, Texas, told KUT News.
 
Flock Safety, backed by $1 billion in venture capital, is clearly reeling from a trend that grew from a squeak of protest into a roar. This is especially true as stories emerge around the country about the misuse of Flock technology by individual police officers for stalking and by Flock personnel for creepy surveillance.
 
Flock is responding. CEO Garrett Langley recently acknowledged and apologized for these shortcomings and announced several operational changes in response.
 
The most salient example is Flock’s reduction of its standard data retention period from a month to seven days. The ACLU, in a sharp but fair analysis of Flock’s changes, conceded that this “may be a step in the right direction.”
 
“Whether this is a real change or just another Flock PR move, however, will depend on how its ‘Evidence Mode’ operates,” the ACLU says. Evidence Mode is a feature that allows law enforcement to preserve specific vehicle and license plate data for ongoing criminal investigations.
 
The ACLU writes:
 
“If ‘Evidence Mode’ only retains hit result data that police determine may be evidence in an active investigation of a specific case, then the change may be a positive one. But if ‘Evidence Mode’ triggers the retention of any ALPR data that is searched, then the new mode could indefinitely retain all of the ALPR data Flock collects and shares nationally.”
 
The ACLU also raised critical questions about Flock’s plans to give communities more control over how their data can be accessed by police in other communities, as well as about the effectiveness of new tools designed to reduce misuse of Flock technology by individual officers.
 
At the same time, it would be a disservice to overlook Flock’s usefulness.
In a recent interview with Detroit’s Local 4 reporter Lauren Kostiuk, Langley quoted a Florida sheriff who speculated that the recent national decline in crime might well be attributable to Flock’s never-blinking eye. Langley credited Flock with helping find than 1,000 missing people and identify 22,000 stolen cars across the United States in one month.
 
Charles Fain Lehman of the Manhattan Institute made similar points in a piece in The Atlantic, “In Defense of Flock.” He wrote that the certainty of apprehension is a powerful disincentive to commit a crime – and that the more surveillance there is, the less crime there will be.
 
Mike Fox, a legal fellow at the Cato Institute, has a trenchant response.
 
“To test Lehman’s thesis, one need only apply his logic to his own doorstep. Imagine if the local police department installed a high-resolution pole camera directed squarely at his front door. By his own logic, Lehman should be elated: The camera would deter prospective burglars and, should an intruder ignore it, capture their every movement in crisp detail to ensure swift apprehension.
 
“Naturally, this arrangement requires government officials to observe every detail of Lehman’s private life. With sufficient resolution, operators could log the packages delivered to his porch, track his every departure and return, note when he walks his dog, and monitor when his children leave for school. Under Lehman’s framework, none of this should disturb him; it is simply the price of crime suppression. His home might never be burglarized, but the cost is continuous state surveillance of his castle.”
 
Even a search of Lehman’s doorstep limited to seven days would be deeply intrusive.
 
Some critics see Flock as an exemplar of surveillance capitalism, although Flock does not own or sell the data its technology generates. (Law enforcement customers own the data.) PPSA has a broader concern, one illustrated by Mike Fox’s thought experiment scaled up to a national system of 120,000 Flock cameras across 49 states.
 
Whatever Flock’s policies and safeguards, our nation is building out a network that could be used by the government to track anyone throughout their daily life. While there is no federal portal into Flock, tracking data in the hands of local law enforcement and perhaps regional “fusion centers” could wend its way upward to politically influenced agencies in Washington, D.C.
 
The greatest danger is that such data could fall into the hands of officials and agencies eager to create dossiers on Americans by tracking our political, business, romantic, and religious associations. In short, Flock could take us down the road to a Russian or Chinese-style surveillance state.
 
That danger is all the more reason for Congress to step in and prevent such an evolution by subjecting the use of data generated by ALPRs to safeguards grounded in the First and Fourth Amendments.
 
Congress should consider requiring warrants before ALPR data may be used to track individual Americans. Congress should also explicitly ban the use of Flock data to monitor how Americans exercise their speech and associational rights in politics, religion, and other sensitive areas.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Supreme Court’s Chatrie Opinion Is a “Blockbuster” that Will Subject High-Tech Spying Systems to New Standards and Scrutiny

8/18/2026

 
Picture
​Six weeks after the U.S. Supreme Court’s 6-3 opinion in Chatrie v. United States, it is just now becoming clear what a breakthrough opinion it actually was.

This ruling leaves an altered legal landscape, one in which courts have fresh opportunities to apply stringent constitutional scrutiny to many intrusive technologies, ranging from automated license plate readers to internet search histories.

At first, this ruling struck many legal observers as a welcome but modest expansion of Fourth Amendment law. Basing its conclusions on recent precedents, the Court held that whenever the government uses a geofence warrant to pinpoint an individual’s location history through cellphone data, it is performing a Fourth Amendment search.

Stanford Law School professor Orin Kerr has now written a sharp analysis contending that Chatrie’s apparently narrow ruling is, in fact, a “blockbuster” that offers the most “rhetorically broad vision of the Fourth Amendment” in 140 years. We think he is right.

Kerr writes that Chatrie “is an expansive pro-privacy opinion that advances new principles and throws into question a wide range of existing surveillance practices.”

The Principle of Consumer Perception

Much of Chatrie’s majority opinion was grounded in precedent, such as Carpenter v. United States. This 2018 ruling held that a warrant is required to track a person’s location history, while limiting that standard to location data collected from cell towers.

“But a close look shows that Chatrie recasts precedents at every turn,” Kerr writes. “Chatrie alters the applicable approaches, adopts new standards, and drops old distinctions.”

For example, a generation ago, the Fourth Amendment was widely understood to prohibit authorities from searching property and “effects” inside a home, a car trunk, or a suspect’s pockets without a warrant based on probable cause. Outside those protected spaces, authorities were – and are – generally free to tail people or rifle through their garbage.

Chatrie demolished this inside/outside distinction. Data held in the cloud can now enjoy a level of protection similar to that of a document in a desk in one’s home. Another way Chatrie goes beyond Carpenter is by bringing users’ perceptions into the equation. Kerr writes:

“It appears that a typical user’s perception of connection with data – generally a matter of app design and interface – can govern whether there are Fourth Amendment rights in the data after the data is disclosed.”

The Intimacy of Data as a Factor
​

Kerr notes that the ruling introduces new concepts into Fourth Amendment law, holding that data generated by ordinary activities on cellphones cannot be presumed to be voluntarily disclosed to third-party tech companies. And Chatrie reorients Fourth Amendment law around the intimacy of private information, rather than the manner in which it was obtained.

Kerr quotes Justice Sonia Sotomayor’s concurrence in a prior case, in which she noted that GPS records contain a “comprehensive record of a person’s public movements that reflects a wealth of detail about her familial, political, professional, religious, and sexual associations.”

This reasoning from one justice in a 2012 case about GPS seems to have filtered into the majority’s thinking about technology in general.

What’s Next?

Where does the law go from here? Some courts will undoubtedly interpret Chatrie narrowly, restricting it to location data. Doing so, however, would ignore the broader implications of Justice Kagan’s majority opinion and its new standards.

We can expect conflicting rulings as lower courts try to apply Chatrie to automated license plate readers, tower dumps, IP addresses, subscriber information, internet search terms, blockchain transactions, and online undercover operations.
​

If lower courts are true to Chatrie, they will recognize a constitutional imperative to apply the Fourth Amendment to curb the unprecedented power of new technology to expose the entirety of a human life. 

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Part I: Flock’s Cameras Were Supposed to Watch for Criminals – Why Were Employees Watching Children?

8/5/2026

 
Picture
Automated license plate readers are sold to communities as straightforward public-safety tools: cameras photograph passing vehicles, record their license plates, and alert police when they detect a car linked to a crime.

But Flock Safety is becoming much more than a network of license plate readers. As the company integrates traffic cameras, police databases, drones, and privately owned video feeds into a surveillance platform, the opportunities for abuse are multiplying.

Mary Rooke of The Daily Caller highlights a disturbing example from Dunwoody, Georgia. Local resident Jason Hunyar used public-records requests to obtain audit logs showing how Flock employees accessed cameras connected to the Dunwoody Police Department’s surveillance system. Some of those cameras were inside the Marcus Jewish Community Center of Atlanta. They showed swimming pools, fitness studios, preschool hallways, and gymnastics rooms where children practiced in their leotards.

Hunyar found that one Flock executive had accessed Dunwoody’s live and recorded footage 185 times since the beginning of 2025. On one occasion, the only camera he viewed was inside the gymnastics room. Another Flock employee clicked through several cameras at the community center before settling on a view of its main pool.

Why were employees of a surveillance vendor looking at these feeds? Why did sales and business-development personnel have such access in the first place?

We should not rule out an innocent explanation. But even if there is one, this story demonstrates the many ways these camera systems can be misused in ways to threaten Americans’ privacy.

A camera installed for one purpose can quietly become part of a much larger system. A feed intended to protect a private facility can become available to police officials, corporate employees, outside agencies, or any hacker who defeats the system’s security. License plate records can be combined with video, location histories, and other databases to produce an increasingly intimate picture of people’s lives.

Communities with Flock technology should require enforceable limits on who may access cameras and data, individualized credentials, prompt disclosure of misuse, independent security testing, and meaningful penalties for improper access. Cameras inside private facilities – especially spaces used by children – should never be swept into police surveillance networks without fully informed consent and exceptionally strong protections.
​
The question is no longer simply whether these systems can help police solve crimes. It is whether any claimed benefit justifies building a surveillance network that may enable strangers to watch us and our children.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Part II: Harrisonburg and Other Cities Tell Flock to Fly Away

8/4/2026

 
Picture
Amid mounting concern about the misuse of personal data from Flock Safety cameras, the college community of Harrisonburg, Virginia, has joined the growing ranks of American communities rejecting that company’s pervasive surveillance of motorists.

The Harrisonburg City Council voted unanimously to end the city’s contract with Flock Safety, shut down its automated license plate readers, and cover the cameras with trash bags until they can be removed. The council also adopted a policy encouraging future councils to consider privacy, data security, equity, and public trust before deploying similar technology. Residents are continuing to press for a binding ordinance that would require public scrutiny of any future mass-surveillance proposal.

Harrisonburg Mayor Deanna Reed acknowledged that Flock cameras can help solve crimes. But she concluded that its risks outweighed its benefits.

“We might not share the data, that doesn’t mean that somebody can’t get a hold of what we have,” Reed told a reporter at WHSV, a local television station. “The safest thing to do is just not use it at all.”

That is a sensible response to a technology that does far more than snap an occasional picture. Flock’s artificial-intelligence system records license plates and vehicle characteristics, allowing police to reconstruct a person’s movements and search for vehicles by color, model, dents, and bumper stickers. Networks linked across jurisdictions can transform scattered observations into a detailed account of where someone worships, works, seeks medical treatment, associates with others, or attends a political protest.

Then there is the problem of accuracy.

A Business Insider investigation found that Flock’s software misread plates in 71 percent of the stolen-vehicle and felony alerts it sent to police in Roseville, California, during 2023 and 2024. Records showed that the cameras also produced blurry images, missed vehicles, and sent delayed alerts. Roseville’s unusual camera positioning may have contributed to the errors, and its police said none of the false alerts resulted in a stop or arrest because officers independently verified the information.

Other communities have not been so fortunate. Flock errors, sometimes compounded by failures of police verification, have led innocent drivers elsewhere to be stopped at gunpoint, jailed, and even mauled by a police dog.

Harrisonburg is part of a genuinely bipartisan revolt. Charlottesville ended its Flock pilot program over concerns about data protection, misuse, and local control. In Bandera, Texas, opposition came from residents steeped in a conservative tradition of personal liberty and distrust of government overreach. Across the ideological spectrum, Americans understand that tools to combat serious crimes can easily expand into routine, warrantless monitoring.

Police should use targeted investigative methods to pursue people reasonably suspected of crimes. They should not assemble a searchable record of everyone’s movements just in case someone might later come to the attention of authorities.
​
Harrisonburg has made the right call. Other communities should follow its lead and tell mass surveillance to get the Flock out.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Pegasus Rears Its Head In Morocco: “We Spy on Everyone”

8/4/2026

 
Picture
We’re shocked – shocked! – to find that spying is going on in Morocco. That country’s intelligence service is using what may be the world’s most powerful spyware to target “journalists, human rights defenders, French politicians and Spanish cabinet ministers and police officers,” according to reporting led by Sam Jones for The Guardian.

The new evidence comes from a whistleblower who previously worked for Morocco’s internal security services and was uncovered in a collaborative journalistic investigation that includes Amnesty International’s Security Lab.

The spyware Morocco is believed to have used includes the infamous Pegasus, which allows its operator to access everything on a target’s mobile phone, including emails, text messages, and photographs. This software does not require the victim to fall for a phishing scam, but can simply install itself remotely. Pegasus can also activate the phone’s recorder and camera, turning it into a 24/7 listening and video-recording device. In July, Security Lab published a technical analysis of Pegasus, labeling it “the world’s most notorious spyware system.”

Pegasus manufacturer NSO Group says it sells its software to governments that need help tracking criminals and terrorists. For its part, Morocco denies having any relationship with NSO. The investigation’s leader Forbidden Stories and its partners found evidence to the contrary.

For entities with an interest in such technology, Pegasus is particularly appealing because, again, it can infect phones remotely – physical access no longer required. This spyware also has the added advantage of erasing any evidence of its existence. What used to be exceedingly difficult – traditional field intelligence – has suddenly become easy.

Perhaps too easy. As described in the accompanying documentary, “Pegasus Project: Inside the Moroccan Spying Machine,” after Morocco’s intelligence service realized what it possessed in Pegasus, its agents quickly added the cell numbers of Moroccan journalists and human rights defenders. Not exactly “criminals and terrorists.”

And before long, The Guardian reports, “the targeting had begun to extend beyond Morocco’s borders,” eventually including 200 Spanish mobile numbers, among them those of the prime minister, the minister of defense, the interior minister, and the minister of agriculture. Spain dropped its initial investigation, only to briefly reopen it after French authorities shared details of their own Pegasus experience.

“We spy on everyone,” a former Moroccan intelligence officer said in conversation with the journalists, “just in case.”
​
It’s all just one more chapter in the unfolding real-life thriller that is the NSO/Pegasus drama.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

“Netflix for Stalkers” – How Flock Exposes Americans to Internet Stalkers

7/27/2026

 
Picture
Imagine taking your child to a playground and later learning that strangers could watch her play live online – or replay it at any time.

Technology researcher and YouTuber Benn Jordan discovered an alarming example of privacy vulnerability – a Flock Safety camera permanently aimed at a playground near the San Francisco Bay Area was openly broadcasting over the internet. No username or password was required.

Jordan and security researcher Jon “GainSec” Gaines found nearly 70 unsecured Flock cameras through a commercial search engine that catalogs internet-connected devices. The cameras were so easy to access that Jordan compared the system to “Netflix for stalkers.”

These were not merely license plate readers. They included Flock’s Condor cameras, which can pan, tilt, and zoom – and use artificial intelligence to detect and follow people automatically. Condor is not a license-plate reader. It is a people watcher.

Jordan says he watched a man leave his home in New York and a woman jog alone on a wooded trail in Georgia. He watched a man rollerblade, stop, and view videos on his phone. The camera’s AI zoomed in closely enough to see what he was watching.
​
Jordan also saw a couple arguing at an Atlanta street market – and used common internet resources to identify their health and financial problems. In another disturbing sequence, he observed emergency responders attending to an apparently injured person. All of this was available to anyone who found the feeds.
The exposure went far beyond live viewing. According to 404 Media, visitors could access administrative controls, download about a month of archived footage, change settings, inspect logs, run diagnostics, and even delete video. Jordan demonstrated the vulnerability by standing beneath one of the cameras and watching himself on his phone in real time.

Flock called the episode a “limited misconfiguration” affecting a small number of devices and said it had corrected the problem. But that response misses the larger lesson.

As Jordan stresses later in his account, responsibility also rests with the local governments that purchase and deploy these systems. City councils and police departments are building interconnected networks of AI-enabled cameras without first demanding rigorous independent security audits, enforceable access controls, clear data-retention limits, and public accountability.

Local officials cannot outsource their responsibility to protect citizens’ privacy. Before approving surveillance technology, they should understand precisely what it records, who can access it, how it can be abused, and what happens when its security fails.
​
A camera installed in the name of public safety should not become an unlocked window into a child’s playground, a couple’s argument, or anyone’s daily life.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Women Around the World Are Learning that “Smart” Glasses Are Spy Glasses

7/27/2026

 
Picture
​In the face of numerous reports that Meta’s AI-powered smartglasses are a potential privacy nightmare, the company is recruiting celebrities like Kylie Jenner to help make its public-relations case to its Gen Z target market. Jenner is savvy enough to have parlayed her fame into a reported net worth of a billion dollars. Though Jenner sits at the intersection of celebrity and wealth, she seems to be glossing over the creep factor – and that may also help to explain the backlash she’s receiving.

It’s also puzzling that Meta tech chief Andrew Bosworth would use a specious argument to dismiss privacy concerns rather than address them directly. When asked about the issue at a press conference, he said: “I’m old enough to remember when there was controversy about phones having cameras, and this predates even the smartphones that we have today. So, there is this social learning thing that has to happen.”

Like learning to give up our privacy and open ourselves to stalking and predation – as women in New York are already having to do? Some women were asked: Where’s your boyfriend? What’s your diet? Have we met before? – questions posed by perfect strangers who happened to be wearing Meta smartglasses. Bosworth seems unaware that social learning is not inherently productive and that smartglasses are far more than the technological equivalent of being able to take a selfie with a smartphone.

Or consider reports of women in Texas who thought they were having genuine interactions with strangers, only to end up as the subjects of social media posts with millions of views – against their wishes. Or consider the women in Brussels, who were filmed without their consent by creepers wearing Meta glasses looking to post footage on online “seduction coaching” sites.

The BBC’s Kali Hays offers even more context in her analysis. A Meta spokesperson told Hays, “We have teams dedicated to limiting and combating misuse, but as with any technology, the onus is ultimately on individual people to not actively exploit it.”

Attorney and privacy advocate David Kessler told Hays: “There are some pretty dark places we could go here. I'm not anti-technology in any sense, but as a societal matter ... will I need to think [of being recorded] anytime I go out in public?”

Meta is taking the approach of trusting that all users will abide by the terms of service and do the right thing. Some users no doubt will, but not all. When we’re talking about matters as fundamental as personal privacy, enacting commonsense laws is the smarter approach.

If an analogy is helpful, think of mandated safety features such as requiring large vehicles to sound a warning when shifting into reverse. After all, as the BBC and many others have pointed out, the minuscule light Meta claims is sufficient to announce that the glasses are in recording mode is laughably inadequate for that purpose.

For the record, not all celebrities are buying what Jenner is selling. Lorde at least had the good sense to call out the privacy issues and push back forcefully on the whole idea. “Can I just say, for the record,” she reportedly told a festival crowd in Madrid, “F--- the glasses. Don't get the glasses. Not sexy.”
​
Because aiming wearable spy tech at nonconsenting adults never is.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FIRST AMENDMENT RIGHTS

More on Mobile Spy Units

7/20/2026

 
Picture
​The story of the mobile spy SUVs purchased by the state of Texas for $4.5 million continues to unfold.

According to Alex Barrientos of Gadget Review, the Texas Department of Public Safety’s purchase of four Chevy Tahoes includes an extra $3.9 million for a proprietary surveillance system from a company named Cognyte, Israel’s version of Palantir. Cognyte is the maker of the FalcoNet surveillance technology embedded in the SUVs.

FalcoNet, writes Andrew Collins of The Drive, has already been deployed in Florida (as has similar stingray technology elsewhere). Its purpose is simple, if ominous: get between cellphone towers and any phones that happen to be near them, and then secretly intercept and capture everything that being transmitted.

FalcoNet and its competitors do this by pretending to be ordinary cell towers, tricking every phone nearby into connecting (smartphones can't help themselves because they are programmed to respond to the strongest signal). Cognyte claims FalcoNet can be activated in under three minutes and can connect with thousands of devices at once as the surveillance vehicles roll through traffic and past pedestrians.

Those intercepts are meant to catch the communications of bad actors being sought by authorities. But the software cannot filter out the private information of bystanders from that of suspects, which means that Texas and Florida are sweeping up the data of everyone who happens to be in the mobile system’s vicinity. The data of thousands of innocent persons can then be sifted through afterward.

This presumes that only law enforcement will do the sifting – and not hackers, data brokers, or hostile state actors. Even so, that is cold comfort given what we know from the actual abuse and potential misuses of similar surveillance systems.

The growing use of stingrays, whether installed on poles in busy parts of town, in mobile police units, or even mounted on drones, underscores the importance of commercial encryption services in protecting our everyday communications. We should be able to enjoy the same level of privacy in our texts and emails that we expect when having a private conversation with a friend.

Equally important, the entire premise of such spy regimes – no matter what the official rationalization – flies in the face of the Fourth Amendment. Designed to protect against the invasive and indiscriminate mass searches of general warrants, the Fourth Amendment offers a simple calculus: probable cause + a court warrant + narrowly defined search criteria.
In their current forms, programs like the aptly named FalcoNet – and it is a net – are functional dragnets, modern-day general warrants that thwart every aspect of the Constitution’s privacy safeguards. Not even outmoded interpretations of the third-party doctrine can (or should) be invoked to save them.

The good news is that we now live in the Chatrie era. In that recent decision, the U.S. Supreme Court clearly articulated a fundamental right to certain forms of digital privacy, specifically regarding location tracking (including geofencing, the whole raison d'être for those shiny new Texas spy SUVs).
​
In short, this practice of roving mass surveillance is ripe for a challenge in court.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Sen. Wyden Calls Out Canada’s Surveillance Bill

7/20/2026

 
Picture
Senator Ron Wyden (D-OR) | PHOTO CREDIT: New America/Flickr
​When PPSA last examined Canada’s proposed Lawful Access Act, we described how it could undermine encryption and endanger privacy worldwide. Now Sen. Ron Wyden (D-OR) is warning that the bill could also enable the Canadian government to conscript American technology companies into spying on Americans.

Bill C-22, which has passed Canada’s House of Commons and is now before the Canadian Senate, would grant authorities in Ottawa sweeping new surveillance powers. It would require service providers to retain sensitive user metadata, such as location information, for up to a year. It could also force companies to alter their systems to facilitate government access or install tracking capabilities and security backdoors. 

In a letter to Secretary of State and acting National Security Adviser Marco Rubio and acting Attorney General Todd Blanche, Sen. Wyden writes that the bill “threatens to weaponize American technology infrastructure by enabling the Canadian government to force U.S. companies to secretly facilitate surveillance of Americans, while systematically undermining the security of their products.”

A foreign government could conceivably pressure an American company to retain special backups of an American target’s data, relocate encryption keys to a jurisdiction where they could be seized, or deliver government spyware through a compromised software update.
The target could be anyone.

As Sen. Wyden warns, “U.S. law does not explicitly prohibit American companies from secretly facilitating foreign surveillance of U.S. citizens – even if the target is the President or another senior U.S. government official.”

“This is not a dilemma of U.S. companies being caught between conflicting international legal obligations,” he writes. “It is a glaring statutory vacuum.” 

Canada is negotiating an agreement with the United States under the CLOUD Act, which would enable Canadian authorities to seek some data directly from American companies. Sen. Wyden urges the Trump Administration to use those negotiations to obtain “ironclad, explicit prohibitions” against Canadian demands that U.S. companies reengineer their products or facilitate surveillance of Americans.

As PPSA has warned, there should be no encryption backdoor reserved for trustworthy governments. Any vulnerability can be exploited by hostile governments, criminals, and increasingly capable artificial intelligence systems.

Sen. Wyden puts the principle succinctly: “Bilateral trust with our closest intelligence partners cannot be built on the secret subversion of American cybersecurity infrastructure.”
​

The Trump administration should heed his warning. Canada must not be permitted to turn American technology companies into instruments of secret spying on Americans.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

The “Eyes of Texas Are Upon You” – The Lone Star State Pays $4.5 Million for Four SUVs with Stingray Spy Devices

7/16/2026

 
Picture
A new report by Andrew P. Collins of The Drive highlights a striking example of how modern surveillance often hides in plain sight: Texas law enforcement recently spent $4.5 million on just four Chevrolet Tahoes.

The SUVs themselves are ordinary enough. What makes them extraordinary is what is concealed inside them – military-grade surveillance technology capable of locating and tracking nearby cell phones. 

The vehicles carry cell-site simulators, commonly known as Stingrays. These devices impersonate legitimate cell towers, compelling nearby phones to connect to them. In doing so, they can identify phones in the area and help authorities pinpoint the location of a target. But the technology does not interact only with suspects’ devices. Every nearby phone can be swept into the dragnet before investigators isolate the device they seek. 

The enormous price tag tells its own story. Texas law enforcement was not just buying SUVs. It was buying an advanced mobile surveillance platform worthy of a Mad Max movie.

Police understandably need effective tools to locate dangerous fugitives, rescue kidnapping victims, and investigate serious crimes. But powerful surveillance technologies should come with equally powerful safeguards.

That is where the Fourth Amendment must draw the line. The government should not be able to exploit technology that silently collects information from countless innocent Americans without rigorous judicial oversight. Warrants based on probable cause should be the rule, not the exception, and agencies should be required to disclose how often these devices are used, under what legal authority, and what happens to data collected from bystanders.

PPSA has long warned that surveillance technologies almost always become cheaper, more capable, and more widespread over time. What begins as an extraordinary capability for rare investigations often evolves into a routine policing tool.
​

The four Tahoes purchased in Texas are a reminder that today’s surveillance state doesn't always arrive as a drone overhead or a camera on a pole. Sometimes it looks like an ordinary SUV moving down the street. The real question is not what such a vehicle costs, but what Americans are giving up every time it rolls by.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

License Plate Readers Are About to Get Even More Personal

7/13/2026

 
Picture
Jacqueline McNeill of Fayetteville, North Carolina, was driving home from the grocery store – with chicken to prepare for her goddaughter’s funeral, no less – when multiple police cruisers cornered her white Nissan Versa in the parking lot of a convenience store.

“I felt like the moment I stepped out of my car,” she later told Tyler Dukes of Raleigh’s The News & Observer, “I was automatically guilty.” The second-grade teacher was arrested on the spot for a drive-by shooting.

Jacqueline wasn’t guilty of anything, but that didn’t stop her from becoming a victim of automated license plate readers (ALPRs). Days before, these roadside cameras had spotted a car similar to hers in the vicinity of a shooting. As with so many other surveillance systems, police used this image in place of critical thinking, as visual proof when it was nothing of the sort.

And now this far-less-than-foolproof technology – with the privacy protections of a rusted colander – is about to get a massive injection of mission creep.

One of the makers of ALPR technology is Leonardo (pro tip before clicking: you might want to decline all cookies). According to Ian Wright of CarBuzz, the company’s SignalTrace technology “is set to move ALPR cameras from just car-tracking to people-tracking devices.” In plain language, that means tracking drivers’ and passengers’ smartphones, vehicle infotainment systems, and any other Bluetooth-capable device – all linked to your license plate or someone else’s.

Worse, our devices are uniquely and individually identifiable. In the absence of robust legislation designed to bolster our Fourth Amendment rights, the only thing that can prevent them from being used as straight-up spy tools by authorities is end-to-end encryption.

Wright reports the SignalTrace product sheet promises to “create a unique, trackable ‘electronic fingerprint’ for investigative use.”

But wait, there’s more! The surveillance dragnet Leonardo is creating includes RFID tags (they’re everywhere, including key cards), pet microchips (so much for taking your dog along on errands), tablets, fitness trackers, tire pressure sensors, and… you get the idea.

If there’s a kicker in all of this, it is another passage Wright quotes from the SignalTrace product sheet, which boasts that it “stores device and correlation data securely … for future queries and analysis.”

The dystopian quantum leap, Wright notes, is that once implemented, ALPR systems will transition from identifying vehicles to identifying occupants. All of this data will be unbound by time, stored in a permanently searchable database – just in case we need to be retroactively suspected of something that may or may not have been legal once upon a time and that we may or may not have done in a car that we may or may not have been driving (or simply riding in).

Calling Steven Spielberg: We just found the sequel to Minority Report.

What could go wrong? To name a few risks: false positives; arrests of innocent people; police officers using ALPR systems for stalking and intimidation; and the collection of massive amounts of personal data by for-profit corporations ready, willing, and able to sell that information to any and all comers, including the government. Add to these risks hacking by cybercriminals and bad-faith state actors. It’s all coming to a technocratic authoritarian surveillance state near you.

Because of her false arrest that day, Jacqueline McNeill never made it to her goddaughter’s funeral. She also largely avoided driving her Nissan before eventually selling it.
​
And who can blame her?

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Stalking with Public Cameras

6/23/2026

 

Especially creepy when cops are the ones getting arrested

Picture
​It’s a bookmark that only privacy advocates would ever think of creating. Maintained by Kansas Watch, it’s a catalog of abuses related to automated license plate readers, called the ALPR Abuse Library. Since 2019, there have been 64 documented incidents in 26 jurisdictions.

Of those, 20 involve stalking or targeting (along with eight other distinct categories of violations). Here are a few of the recent stalking entries, each of which the site links to original sources:

  • Former officer used police databased to track his mistress and harass her with thousands of texts and phone calls
 
  • Ex-detective misused police resources to track spouse; child sex abuse material found
 
  • Sheriff used Flock cameras to search for wife’s vehicle
​
  • Police officer allegedly used department database to stalk woman he met on at a television shoot

According to the Institute for Justice (IJ), which also tracks such police-related incidents, the root cause is one we’ve discussed many times: the complete absence of a search warrant as required by the Fourth Amendment, which, warns IJ, “predictably allows officers to abuse their access to these systems for things like stalking romantic partners.”

For those concerned about potential abuse of ALPR systems (particularly those made by Flock Safety), one place to begin is to see if your license plate shows up in publicly available search databases such as Have I Been Flocked. IJ also operates an education and advocacy site devoted to fighting the unconstitutionality of ALPR technology, called The Plate Privacy Project.

The warrant requirement in the Constitution precedes the electronic era. The Founders’ primary reason for including it was a concept as familiar then as it is relevant now: Searches that are overly broad, unsupported by cause, and conducted without oversight are sure to be abused – a danger the Founders knew was ripe for exploitation in any age.
​
When police can misuse ALPRs for petty, personal reasons, the eventual abuse of these systems by government officials for larger political reasons is virtually assured.

Mercenary Spyware Goes Mainstream, Part II

6/23/2026

 

Your smartphone can become a 24/7 surveillance device without you making a single wrong click

Picture
​In our last post, we reported on leaks that reveal that the Bulgarian government has approved the export of advanced spy technologies to governments around the world, many of them with poor ratings for their treatment of human rights, press freedoms, and political dissent.
 
Thanks to this technology, tyrants, tormentors, and regimes around the world have gained unprecedented capabilities to intercept communications, track individuals, and harvest sensitive personal data – texts, emails, and calls – through defects in global telecommunications systems.
 
Who is behind this privacy apocalypse?
 
The Same Players Keep Appearing
 
Human Rights Watch notes that the company selling these exploits, Circles, was founded by Tal Dilian, who also founded Intellexa, maker of the Predator zero-click tool. Dilian was sanctioned by the United States in 2024 for activities connected to the development and distribution of commercial spyware used against journalists, dissidents, policy experts, and government officials. Circles itself also has historical ties to NSO Group, the maker of Pegasus. 
 
The result is an ecosystem in which a relatively small group of firms and executives have repeatedly surfaced in controversies involving surveillance abuses around the world. Their activities demonstrate how interconnected the commercial spyware industry has become.
 
A Growing Threat to Privacy and Democracy
 
Such technologies often operate in secrecy, with little transparency, limited judicial oversight, and no remedies for victims.
 
Human Rights Watch recently documented how surveillance technologies exported from European countries have been used by governments to target journalists, activists, academics, humanitarian workers, and political critics. The organization concluded that existing controls are failing to prevent sales to countries where there is a substantial risk of abuse. 
 
Figures ranging from journalists in Mexico and India to opposition politicians in Spain, and even a British prime minister, have been targeted by Pegasus software. With the expansive growth of Circles’ new surveillance software, Americans should wake up and realize that we are not immune to this global trend.
 
As PPSA noted in our original reporting on mercenary spyware, American officials have already been targeted by foreign spyware campaigns. The proliferation of these capabilities means that sophisticated digital surveillance is becoming cheaper, more accessible, and harder to contain. 
 
The Lesson
 
The leaked Bulgarian licenses provide another reminder that surveillance technology does not stay confined to the governments that first develop it. In short, the spread of mercenary spyware was once viewed as an emerging problem. Today, it is a mature global industry.
 
The dangers posed by these sophisticated attacks have long been foreshadowed in Congressional testimony and hearings. Yet solutions are not obvious or easy. Like narcotics, surveillance tech often spreads through international markets, private vendors, shell companies, and workarounds of export controls until powerful interception capabilities become available to governments around the world, as well as criminals and cartels.
 
Congress and policymakers must now recognize that this global marketplace for commercial spying tools is thriving and potentially threatens any American. The question is whether democratic governments will establish meaningful safeguards before these technologies become even more pervasive – and even more difficult to control.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Mercenary Spyware Goes Mainstream, Part I

6/22/2026

 

Your smartphone can become a 24/7 surveillance device without you making a single wrong click

Picture
​Four years ago, PPSA warned about the rise of “mercenary spyware” – powerful surveillance tools once reserved for elite intelligence agencies that were rapidly becoming available around the world. The poster child for this trend was Pegasus, the Israeli-developed “zero-click” spyware capable of silently taking over a smartphone, activating its camera and microphone, turning it into a full-time surveillance device that extracts nearly every detail of a person’s life. 
 
Human Rights Watch reports that the market for such dystopian surveillance technology is now truly global.
 
A new investigation based on leaked Bulgarian export licenses reveals that a surveillance company called Circles received approval to export similarly sophisticated communications interception and phone-tracking technologies to a wide range of foreign governments between 2018 and 2023. According to the documents, Bulgarian authorities licensed exports to Azerbaijan, Bahrain, Brazil, the Dominican Republic, El Salvador, Ghana, Guatemala, Israel, Jordan, Malaysia, Mexico, Morocco, Panama, Serbia, and the United Arab Emirates. 
 
The governments of many of these countries have been criticized by human rights organizations for surveillance abuses, restrictions on press freedom, and crackdowns on political dissent. Human Rights Watch concluded that the licenses raise serious questions about whether European export controls designed to prevent abusive surveillance exports are being enforced. 
 
What Can These Systems Do?
 
The leaked documents describe a suite of surveillance products that far surpass traditional wiretaps. Unlike Pegasus, a “zero-click” capability that could remotely infect your smartphone without you making a single wrong click, Circles’ technology exploits chinks in the global telecommunications infrastructure, capturing your data as it is transmitted.  
 
Among the exported technologies were:
 
  • Software capable of tracking the locations of mobile subscribers
 
  • Systems that can remotely intercept voice calls and communications data through weaknesses in global telecommunications infrastructure
 
  • Tools designed to facilitate targeted interception of communications
 
  • Software that can collect voice, message, and internet traffic from cellular devices
 
As one expert warned Congress in testimony highlighted by PPSA in 2022, capabilities once available only to a few nation-states are now available to dozens. CrowdStrike reports an 89 percent increase this year in AI-enabled  attacks. The most advanced surveillance technologies are no longer confined to a handful of superpowers. They could be in the hands of almost any government – and, before long, in the hands of your competitors or personal enemies.
 
In our next post on this topic, we will look at the corporate entities fomenting this global privacy disaster, the implications for privacy and democracy, and the need for Congress and the administration to develop responses.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

China’s “Holographic Profiles” Show the Future of Mass Surveillance

6/3/2026

 
Picture
​We’ve long chronicled how China is building the world’s most sophisticated surveillance state. Cameras equipped with facial recognition software, biometric databases, digital tracking systems, and artificial intelligence have become commonplace across the country.

Now, newly reported details reveal a Chinese surveillance apparatus that is even more expansive and well-integrated than previously understood.

In a report by De Zheng for DW, a cybersecurity researcher discovered an exposed Chinese police database connected to a platform known as “Bright Eyes.” The system reportedly maintained extensive records on foreign journalists, visitors, and residents, including passport photographs, visa information, travel histories, and other personal details.

But what makes Bright Eyes remarkable is not merely the quantity of data it collects. It is the way the system combines disparate information into what Chinese authorities call a “holistic personnel archive,” creating “holographic profiles” of individuals.

According to the report, Bright Eyes integrates data from facial-recognition cameras, immigration records, hotel registrations, transportation systems, mobile-phone identifiers, and other databases. The system reportedly can identify not only that a person traveled but also precisely where that person sat on a train, when he entered a venue, and who was nearby.

De Zheng notes: “It even synchronizes photos from different camera systems and checkpoints, creating a continuous visual record of a person's movements.”

Because the system has access to multiple streams of information, authorities can reconstruct a person's activities with extraordinary precision. Officials can analyze not only an individual's movements but also relationships, routines, and patterns of behavior over time.
Perhaps most striking is the system's apparent emphasis on social connections.

The report describes analytical tools designed to determine “how frequently targets are captured interacting on camera, revealing exactly who knows who, and how much time they spend together.” The system maps human networks for social and political analysis.

China’s surveillance architecture offers a warning about the direction technology can take when constitutional constraints are absent. The technologies involved – artificial intelligence, facial recognition, data aggregation, and predictive analytics – are becoming more powerful.

The Solomon Islands in the South Pacific provide a stark example of how this surveillance state can be exported. David Pierson and Berry Wang of The New York Times detailed the pushback by local residents after China installed its “model police state” through a secret agreement with that country’s government.

The Australian Strategic Policy Institute warned that the Solomon Islands is becoming China’s “proving ground for authoritarian practices under the guise of community service.” An official mouthpiece of the Chinese government described such Western reactions as “the discomfort of former colonial powers whose exclusive influence in the Pacific is no longer assured.”

But who is the real imperialist in this scenario?

The lesson for Americans is straightforward. Privacy is more than a setting. It is the condition that makes free speech, free association, religious liberty, and a free press possible. Once governments acquire the ability to know everything about everyone, the freedoms guaranteed by the First and Fourth Amendments become increasingly difficult to exercise in practice.

China’s “holographic profiles” show why constitutional limits on surveillance matter now more than ever. That’s something for Congress to keep in mind when it considers whether to revisit surveillance policy in the ongoing Section 702 debate in two years or much longer.
​
The speed at which artificial intelligence is evolving should lead Americans to insist that Congress keep a tight leash on any would-be American version of Bright Eyes.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

School Buses as Mobile Surveillance Units: How Child Safety Concerns Can Be Hijacked to Build a “Hellscape of Surveillance”

6/2/2026

 
Picture
​When you hear of a new surveillance program being marketed as a child-safety initiative, give it particularly close scrutiny. History shows that the narrower and more compelling the stated justification for a surveillance plan, the broader and more outlandish the surveillance will actually be.

A newly reported example comes from BusPatrol, a company that has installed AI-powered camera systems on more than 40,000 school buses in 24 states. The cameras have been marketed as a way to identify drivers who ignore the fold-out “STOP” arm signs from buses and illegally pass them while stopped. 

Joseph Cox of 404 Media reports that BusPatrol is now planning a dramatic expansion of its mission. Leaked company documents reportedly show plans to convert school buses into roaming automatic license plate reader (ALPR) platforms that would capture information on every vehicle a bus passes, regardless of whether any crime or traffic violation occurred. The resulting data would then be sold to law enforcement. 

A system designed to document a specific violation at a specific moment is fundamentally different from a system that continuously records the movements of everyone nearby. In effect, school buses would become mobile surveillance vehicles.

Under the proposal, cameras would photograph vehicles, record their license plate numbers, and attach GPS location data. Law enforcement and possibly other actors could then query those records to reconstruct a vehicle's travel history. As privacy advocates have long warned, tracking a car often means tracking a person. 

These bait-and-switch tactics are familiar.

After the attacks of September 11, Americans were told that extraordinary surveillance programs were necessary to prevent terrorism. Many of those authorities later expanded far beyond their original scope. Section 702 of FISA was enacted to monitor foreign threats overseas, yet the communications of millions of Americans became subject to warrantless searches.

From the UK to Congress, we’ve seen how the fight against child sexual abuse material has been used as a shield to threaten the encryption that protects women and children from stalkers, journalists from vengeful politicians, businesses communicating about proprietary information, and millions of law-abiding Americans who want to have a digital conversation without Big Brother listening in.

Government agencies have repeatedly justified the acquisition of vast quantities of personal data by pointing to legitimate public concerns, only for those powers to evolve into broader surveillance tools.

BusPatrol's reported plans follow the same trajectory. A narrowly tailored safety program aimed at preventing children from being struck by passing vehicles could become a platform for collecting location information on millions of ordinary Americans who have done nothing wrong.

The danger is not merely the collection of data. It is the normalization of surveillance infrastructure. Every new camera network creates pressure to find new uses for the information it gathers. Indeed, BusPatrol’s internal documents suggest that this latest move is in response to investor demands for new revenue streams.

Protecting children is a worthy goal. Turning school buses into rolling location-tracking platforms is not.
​
Americans should be wary whenever government agencies or private contractors ask them to trade away privacy in exchange for safety. Proposals like this need their own mounted “STOP” arm signs.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

What a Small Texas Town’s Rebellion Against Surveillance Tells Us About the National Appeal of Surveillance Reform

5/25/2026

 
Picture
​We don’t condone vandalism. But we have to admit that a recent event in the Texas Hill Country town of Bandera showed a flash of the spirit of the Boston Tea Party, or, perhaps more appropriately, of the settlers in the East Texas town of Gonzales who, in 1835, cried “Come and Take It!” while firing their small brass cannon at the Mexican Army.

We’re talking about the repeated efforts of the Bandera city council to install eight AI-enhanced license plate readers on poles around the town, only to have local residents use saws to cut the poles in half and take down the cameras. After several rounds of this rebellion, the city council finally gave up and ended its contract with Flock Safety, a company that is building a national network of cameras that track cars and store the daily movements of millions of Americans.

Brian McManus chronicles this contest of wills in Courier Texas.

“Bandera is the cowboy capital of the world,” one resident told McManus. “We don’t need to implement mass government surveillance in our town.”

McManus reports that Bandera has a lower crime rate than both the Texas and national averages. Banderans just didn’t like the idea of “ordinary people going about their ordinary lives in a town where everybody already knows everybody.”

There is one aspect of this story that touches on something of national significance. McManus writes:

“This was not a left-versus-right argument. It was rooted in community and the instinct toward personal liberty and suspicion of government overreach that defines much of rural Texas political identity. The irony that a surveillance state program backed by Republican state grant money ran headlong into Republican small-town resistance was not lost on people in the [city council] room.”

While Congress debates surveillance policy, it is clear that national concern about the need to protect the privacy and constitutional rights of the American people cuts across party and ideological lines.

Advocacy for reform amendments to FISA Section 702 comes from Rep. Andy Biggs (R-AZ) and Rep. Zoe Lofgren (D-CA), as well as Sen. Mike Lee (R-UT) and Sen. Ron Wyden (D-OR). Can you think of any other issue that unites staunch conservatives and stalwart liberals?

All of them and many more are backing measures to keep the government’s hands off Americans’ personal data without warrants, as the Constitution requires.
​
They might agree with one Bandera resident who told McManus that surveillance “just doesn’t pass the vibe check.” Neither does the federal government’s warrantless collection and inspection of Americans’ personal data.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Is That a “0” or an “O”? Your Freedom May Depend on It

5/5/2026

 

Colorado Man’s Flock Nightmare

Picture
​Futurism and other sources report that Kyle Dausman can’t go anywhere in his truck without being swarmed by police. It’s all thanks to a glitch in the Matrix – er, in the Flock Safety camera surveillance system – used by authorities across the state of Colorado. Seriously, this is one of those stories that would be a lot funnier if it were about an average guy named Klaus who lived in the East German police state circa 1986.
 
After stopping him a couple of times, the Cherry Hills Police Department quickly realized that a dubious clerical strategy was responsible for flagging local resident Dausman in the statewide Colorado Crime Information Center database. Because the Centennial State, like others, uses both zeroes and letter Os in license numbers: “Sometimes the data entry will be for both" versions of a plate when an arrest warrant is issued, Cherry Hills police chief Jason Lyons told Denver’s KUSA.
 
A clerk filing a warrant in another county apparently did exactly that in Kyle Dausman’s case, entering both the “0” and “O” versions of the actual offender’s tag, according to the Cherry Hills chief. He also noted, pointedly: "It wasn't a mistake.” Poor Dausman just happened to be the guy with the innocent-yet-incorrect tag sequence. "Everywhere in the state, every time I pass a camera,” laments the victim, “they get alerts in their car that I'm in the area." He justifiably worries for his family’s safety as well as his own.
 
Colorado should order its clerks to stop conflating zeros and Os. Why does the state – like many others – continue to put innocent people in harm’s way? This could be fixed with one executive order from the governor.
 
At least the local police department in Cherry Hills fixed the flag in its local database. But beyond that, Dausman is on his own, and largely without recourse according to the details of various reports: The Colorado Crime Information Center hotlist still shows him as a wanted man, and no one is sure who has the actual authority to address the situation. All of which is to say nothing of actual reform (which lives only on best practice wish lists for now).
 
Dausman’s experience, writes Al Landau for Gadget Review, is emblematic of a fundamental problem with large-scale, big-data-powered surveillance systems like the Flock Safety networks popular across Colorado: “Flawed data produces harmful results, regardless of camera sophistication.” A process, he says, that amplifies bad data practices, potentially turning them into “major personal nightmares.”
 
Like a coal miner’s canary, this story warns not just about the anti-privacy plate-reader industry, but about the dangers of public partnerships with Big Tech that fuels the growth of the modern surveillance state.
 
In the meantime, privacy-loving pro-Fourth-Amendment citizens who want to keep tabs on Flock’s invasive alliances with law enforcement can do so on an advocacy site appropriately called DeFlock.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

Does Congress Understand the Intelligence Programs It Oversees?

4/7/2026

 
Picture
U.S. Representative Jim Himes (Left). PHOTO CREDIT: USAID
​The American Prospect reports that statements made by Rep. Jim Himes (D-CT), Ranking Member of the House Permanent Select Committee on Intelligence, are raising the question of how well Members of Congress understand the surveillance authorities they oversee.

​“I am not aware of any NSA purchases of U.S. person data,” Rep. Himes is quoted as saying in a virtual town hall last week. “And because their targets, by law, are exclusively foreign, they … have no reason and no business buying American data.”

Okay @jahimes, here’s 2 minutes of you saying NSA doesn’t buy our data (it does). https://t.co/PM4NV2wVsq pic.twitter.com/Ve8IMC9Rza

— QuitGPT (@quitchatgpt) April 7, 2026
​
​We agree with the last part of that statement. If only the first part were true.
 
In a letter sent in 2023 in response to a query from Sen. Ron Wyden (D-OR), then-NSA Director Gen. Paul Nakasone wrote: “NSA acquires various types of CAI (commercially available information) for foreign intelligence, cybersecurity, and other authorized mission purposes, to include enhancing its signals intelligence (SIGINT) and cybersecurity missions. This may include information associated with electronic devices being
used outside and, in certain cases, inside the United States.”
 
Charlie Savage of The New York Times summarized the letter’s content thusly, “The National Security Agency buys certain logs related to Americans’ domestic internet activities from commercial data brokers.” This characterization was under the headline, “N.S.A. Buys Americans’ Internet Data Without Warrants, Letter Says.”
 
Rep. Himes also said that AI “has absolutely nothing to do with 702. Nothing. Full stop.”
 
The American Prospect reports that the Department of Justice’s National Security Division (NSD) budget justification shows that NSD “worked closely” with the intelligence community “to discuss new AI tools that are involved in processing or analyzing FISA-acquired information.”
 
All of which suggests that before the House debates the reauthorization of FISA Section 702 – a program that authorizes foreign surveillance on foreign soil but has often been used to warrantlessly spy on Americans on U.S soil – a deeper discussion with civil liberties groups and a robust House debate are warranted.
 
In facing the looming Section 702 debate, Members of the House need to hear from all sides of the surveillance debate – not just the approved line from the executive branch intelligence agencies.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS

How Hackers Can Use Tire Sensors to Track Your Driving Habits

3/9/2026

 
Picture
​The Internet of Things (IoT) strikes again. Most modern vehicles possess a tire pressure monitoring system (TPMS), a legal requirement since 2007. A recent study shows that it is possible to capture unencrypted Wi-Fi messages sent by TPMS sensors. Each sensor sends a unique ID number, which makes tracking specific vehicles child’s play for a hacker.

Think about this for a moment – the average car or truck is broadcasting four such unique IDs (one per tire), with no need for license plate readers with high-tech cameras and AI software. That, says the IMDEA Networks Institute, “makes TPMS-based tracking cheaper, harder to detect, and more difficult to avoid than camera-based surveillance, and therefore a stronger privacy threat.”

A motivated hacker need only place a series of low-cost receivers near the appropriate parking lots and roads. Within weeks:

“These tire sensor signals can be used to follow vehicles and learn their movement patterns. This means a network of inexpensive wireless receivers could quietly monitor the patterns of cars in real-world environments. Such information could reveal daily routines, such as work arrival times or travel habits.”

It gets worse: TPMS signals can even be captured from moving vehicles. Some sensors reveal actual tire pressure values (as opposed to merely “Low”), which could, for example, be used to determine if a vehicle is carrying a heavy payload or to distinguish vehicles by type. Pretty soon we’re in Mission: Impossible territory.

As is so often the case with the IoT, safety was the motivation behind the development of tire pressure monitoring systems in the first place. Because privacy was never a consideration, privacy-by-design protections were missing from the start. The result is a familiar IoT pattern: unencrypted signals and wide-open vulnerabilities becoming the rule rather than the exception. When it comes to privacy issues, safety never seems to stay in its lane.

“Our findings show the need for manufacturers and regulators to improve protection in future vehicle sensor systems,” notes researcher Yago Lizarribar. If nothing changes, yet another safety tool will be perverted into an instrument of general population surveillance.

But change does not seem to be an industry priority. As Aaron Pruner of CNET points out, we’ve had sixteen years to address this vulnerability. A study by Rutgers University and the University of South Carolina identified the problem in 2010, a mere three years after TPMS was mandated.
​
Which means that if TPMS sensors were kids, they’d be old enough by now to start driving – and be tracked every mile of the way.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US PROTECT YOUR FOURTH AMENDMENT RIGHTS

What the Anthropic/OpenAI Story Is Really About

3/8/2026

 
Picture
​The media reported on the drama of the Pentagon’s AI contracts as a horse race: Anthropic tried to limit what the War Department could do with the company's Claude AI product. The administration subsequently rescinded all government contracts with the company. OpenAI offered its products as the alternative and won the day.

But beneath this drama lies a deeper and more dangerous reality: In the absence of meaningful guardrails, the AI tech of any company can be used for surveillance and – if combined with data collected under Section 702 of the Foreign Intelligence Surveillance Act (FISA) – could allow government employees across the federal bureaucracy to run searches on Americans’ private communications.

Such AI-powered surveillance could extend far beyond the Department of War’s use cases and even the Justice Department’s FBI investigations. Government AI-enabled mass surveillance of the domestic population would:

  • Not be subject to any oversight authority – constitutional or statutory
 
  • Not be encumbered by recent reforms like 2024 RISAA (Reforming Intelligence and Securing America Act)
 
  • Be supercharged by the dismantling of long-standing information silos and the removal of safeguards that once limited the sharing of Americans’ private data between agencies – from the Department of Homeland Security to the IRS.
 
  • All done without a warrant – without any court supervision of the government’s invasion of your privacy.

The danger of AI surveillance in a government that shares data between agencies should prompt Congress to strengthen Fourth Amendment privacy protections. With such a vast datascape available to the world's most powerful government – where many existing restrictions have already been weakened – we otherwise risk the irrevocable loss of personal privacy and the rise of a permanent surveillance state.

We need to come to terms with the fact that AI tech makes rummaging through our private lives and personal histories easier and faster than anyone could have imagined even a few years ago. Americans’ communications could become permanently accessible to the prying eyes of government agents in almost any agency with a whim (or a political directive) to pursue.

It wasn't supposed to be this way. AI was supposed to have guardrails, as was Section 702, enacted by Congress to enable the surveillance of foreign threats on foreign soil, but has instead been used by the government to search the private communications of Americans without a warrant.

RISAA was a noble attempt to rein in the misuse of Section 702 as a domestic spy tool. Its reforms included oversight and restrictions on FBI searches involving people inside the United States. It implemented rules for queries involving high-profile groups or individuals. It established training and accountability measures, while enhancing oversight of the two secret courts FISA created.
​
These were important reforms, but they were weakened by last-minute changes to the bill. When Section 702 comes up for renewal next month – this time in the context of an AI juggernaut – it may well be our last chance to protect our freedoms while protecting national security. 

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US PROTECT YOUR FOURTH AMENDMENT RIGHTS

Meta’s AI Training Includes Smart Glasses Footage Capturing Users Undressing, Having Sex, Sitting on the Toilet

3/5/2026

 
Picture
​There is a point early in a marriage when spouses get comfortable and uninhibited around each other in the bedroom and even the bathroom. That’s because there is no third set of eyes in the room… unless one of them just happens to be wearing a pair of smart glasses.

We recently covered the perils and pitfalls of Meta adding facial recognition software to its Ray-Ban smartglasses. Now Victor Tangermann of Futurism has uncovered a genuine horror story about private images captured by these glasses, millions of which are already in circulation.

Meta, in order to refine its AI imaging, sends footage from consumers’ glasses to contractors in Kenya and other countries to label them for training. This tedious process is necessary to enable AI to learn to recognize everyday objects.

At that point, almost anything recorded by Meta glasses is liable to be sent abroad for data annotation.

“I saw a video, where a man puts the glasses on the bedside table and leaves the room,” one data annotator told two newspapers in Sweden. “Shortly afterwards his wife comes in and changes her clothes.”

Another data annotator said: “In some videos you see someone going to the toilet, or getting undressed.”

Tangermann reports that other footage included “imagery of people’s bank cards, users watching porn, or even filming entire ‘sex scenes.’”

Meta customers have no recourse. Data protection lawyer Kleanthi Sardeli told the Swedish press, “Once the material has been fed into the models, the user in practice loses control over how it is used.”
​
Of course, as the Internet of Things weaves together Ring cameras, cloud-based voice-activated AI assistants, baby monitors, and robot vacuums, we are all subject to being surreptitiously recorded at, well, inconvenient moments. But none of them have the reach into personal privacy that happens when one spouse is wearing a pair of smart glasses and the other announces that the toilet paper holder is empty.

    STAY UP TO DATE

Subscribe to Newsletter
DONATE & HELP US DEFEND YOUR FOURTH AMENDMENT RIGHTS
<<Previous

    Categories

    All
    2022 Year In Review
    2023 Year In Review
    2024 Year In Review
    2025 Year In Review
    Analysis
    Artificial Intelligence (AI)
    Biometric Data
    Call To Action
    Congress
    Congressional Hearings
    Congressional Unmasking
    Court Appeals
    Court Hearings
    Court Rulings
    Data Privacy
    Digital Privacy
    Domestic Surveillance
    Due Process
    Facial Recognition
    FISA
    FISA Reform
    FOIA Requests
    Foreign Surveillance
    Fourth Amendment
    Fourth Amendment Is Not For Sale Act
    Government Surveillance
    Government Surveillance Reform Act (GSRA)
    Insights
    In The Media
    Lawsuits
    Legal
    Legislation
    Letters To Congress
    NDO Fairness Act
    News
    Opinion
    Podcast
    PPSA Amicus Briefs
    Private Data Brokers
    Protect Liberty Act (PLEWSA)
    Saving Privacy Act
    SCOTUS
    SCOTUS Rulings
    Section 702
    Spyware
    Stingrays
    Surveillance Issues
    Surveillance Technology
    The GSRA
    The SAFE Act
    The White House
    Warrantless Searches
    Watching The Watchers

    RSS Feed

FOLLOW PPSA: 
© COPYRIGHT 2026. ALL RIGHTS RESERVED. | PRIVACY STATEMENT
Photo from coffee-rank