DOJ Hid from FISA Court that Surveillance Targets Were Members of Congress and Key Oversight Staff12/17/2024
The first reactions to a report issued last week by Department of Justice Inspector General Michael Horowitz centered on the man-bites-dog irony of the Justice Department having spied on the nominee to head the FBI, Kash Patel. The underlying story is far bigger and as significant as any other of recent surveillance scandals – Horowitz revealed that the government’s lawyers failed to inform a judge in the secret FISA Court that their applications for surveillance were to spy on Members of Congress and senior congressional aides on committees that oversee the Department of Justice. It’s as if you asked a friend if you could borrow her car to go to the store but forget to tell her that the store is in Mexico. Justice Department prosecutors showed just about that level of mendacity in 2017 when they sought communications of Members of Congress, including then-House Intelligence Committee Chairman, Rep. Adam Schiff (D-CA), and Rep. Erik Swalwell (D-CA), 20 Democratic staffers, as well as Patel and 19 other Republican staffers. The intent of the request was to reveal if there was cause-and-effect between their emails and journalists at The Washington Post, The New York Times, and CNN, who wrote stories in those outlets based on a classified leak of “Top Secret/Sensitive Compartmentalized” documents. As it turned out, no crimes or leaks were discovered. Horowitz reveals that DOJ obtained 40 Non-Disclosure Orders forcing communications providers to secretly provide the records of Members of Congress and staffers, with some of the search orders extended up to four years – even though the request involved leaks around the same time frame in 2017. Horowitz concludes:
The Justice Department’s policy did not, at that time, have an internal policy governing the compelled acquisition of congressional communication records from third-parties. Perhaps feeling the heat from outraged Members of Congress, Justice established the requirement in future applications to inform the Justice Department’s Public Integrity Section and a U.S. attorney before surveilling Members of Congress and their staffers in this way. Horowitz found that process insufficient, calling on a new policy that requires the informing of the Attorney General or the Deputy Attorney General. Concerning the surveillance of journalists, Horowitz found that the Justice Department did not comply with all of its internal provisions. For example, a committee dedicated to applications for media surveillance was not convened, as required by Justice Department policy. That policy also required informing the Director of National Intelligence, which the Justice Department did not do in at least one instance. PPSA believes the intelligence agencies are surveilling Congress in many other ways. That is why we have sued not just the Department of Justice, but also the NSA, the FBI, the CIA, and the State Department to learn if these agencies are surveilling current and former Members of Congress with oversight responsibilities over those very agencies. If the intelligence community is surveilling Members of Congress on the Intelligence and Judiciary Committees, then it is a case of the overseen overseeing the overseers. This danger is made much worse by House policies, where relatively few House staffers have security clearances that would allow them to help their bosses keep the intelligence agencies in check. We hope at a minimum that the House will widen staffer clearances, as the Senate has done, to assist in greater oversight of these agencies. We especially hope that incoming President Trump will have his people dig into the practice of surveilling Members of Congress and bring it to light. Expansive Spy Law Even Targets Churches Breitbart recently broke a story that a few recalcitrant House Members are holding up a promised fix to what many referred to as the “Make Everyone a Spy” law. The fix regards an amendment to the reauthorization of FISA Section 702, passed in April, in which pro-surveillance advocates added a requirement that U.S. business owners who offer customers the use of their Wi-Fi and routing equipment be covered as “electronic communication service providers” under the law. This means that any business – your neighborhood fitness center, an office complex that houses journalists, political campaigns, or even a church or other house of worship, as well as a host of other establishments – would face the same requirement as large telecoms to turn over the communications of their customers, no warrant required. This was not meant to happen. As the Senate voted in April to reauthorize FISA Section 702, bipartisan furor erupted over this provision, including leading conservatives in both chambers. Sen. Mark Warner (D-VA), Chairman of the Senate Intelligence Committee, promised his colleagues that the amendment that included this expansive authority would be narrowed to include only one category of business. That category is classified but is widely believed to be data centers that provide cloud computing and storage. With this promise in hand, the Senate voted down an amendment to remove the flawed provision, and immediately passed the reauthorization of Section 702 – all in the belief that the expansive new spy power would soon be curbed. Sen. Warner was true to his word, inserting language into the Senate intelligence bill that narrows the scope of the new measure. Now, in a baffling turn of events, it is the House that is refusing to include the fix in its version of the intelligence bill. Why are some House Members insisting on keeping an authority that allows spying on churchgoers, shoppers, and office workers? Bob Goodlatte, the former chairman of the House Judiciary Committee and PPSA senior policy advisor, told Breitbart News: “This measure passed because of assurances that this insanely broad authority would be narrowed. The promise of a fix was made and accepted in good faith, but that promise is being trashed by advocates for greater surveillance of our citizens. Unless Congress reverses course, Americans’ data that runs through the Wi-Fi and servers of millions of small businesses, ranging from fitness centers to department stores, small office complexes, as well as churches and other houses of worship, will be fair game for warrantless review. This would truly transform our country into a thorough surveillance state. I can’t imagine the next Congress and new Administration would welcome that.” Surely, giving the deep state free rein to spy on Americans is not in keeping with the philosophy of the incoming Trump administration, the new Republican majority in Congress, or most Democrats. Contact your House Member and say: “Please don’t let this legislative year end without narrowing the Electronic Communication Service Provider standard. Congress must keep its promise to fix the Make Everyone a Spy Law.” Why Signal Refuses to Give Government Backdoor Access to Americans’ Encrypted Communications11/4/2024
Signal is an instant messenger app operated by a non-profit to enable private conversations between users protected by end-to-end encryption. Governments hate that. From Australia, to Canada, to the EU, to the United States, democratic governments are exerting ever-greater pressure on companies like Telegram and Signal to give them backdoor entry into the private communications of their users. So far, these instant messaging companies don’t have access to users’ messages, chat lists, groups, contacts, stickers, profile names or avatars. If served with a probable cause warrant, these tech companies couldn’t respond if they wanted to. The Department of Justice under both Republican and Democratic administrations continue to press for backdoors to breach the privacy of these communications, citing the threat of terrorism and human trafficking as the reason. What could be wrong with that? In 2020, Martin Kaste of NPR told listeners that “as most computer scientists will tell you, when you build a secret way into an encrypted system for the good guys, it ends up getting hacked by the bad guys.” Kaste’s statement turned out to be prescient. AT&T, Verizon and other communications carriers complied with U.S. government requests and placed backdoors on their services. As a result, a Chinese hacking group with the moniker Salt Typhoon found a way to exploit these points of entry into America’s broadband networks. In September, U.S. intelligence revealed that China gained access through these backdoors to enact surveillance on American internet traffic and data of millions of Americans and U.S. businesses of all sizes. The consequences of this attack are still being evaluated, but they are already regarded as among of the most catastrophic breaches in U.S. history. There are more than just purely practical reasons for supporting encryption. Meredith Whittaker, president of Signal, delves into the deeper philosophical issues of what society would be like if there were no private communications at all in a talk with Robert Safian, former editor-in-chief of Fast Company. “For hundreds of thousands of years of human history, the norm for communicating with each other, with the people we loved, with the people we dealt with, with our world, was privacy,” Whittaker told Safian in a podcast. “We walk down the street, we’re having a conversation. We don’t assume that’s going into some database owned by a company in Mountain View.” Today, moreover, the company in Mountain View transfers the data to a data broker, who then sells it – including your search history, communications and other private information – to about a dozen federal agencies that can hold and access your information without a warrant. When it comes to our expectations of privacy, we are like the proverbial frogs being boiled by degrees. Whittaker says that this is a “trend that really has crept up in the last 20, 30 years without, I believe, clear social consent that a handful of private companies somehow have access to more intimate data and dossiers about all of us than has ever existed in human history.” Whittaker says that Signal is “rebuilding the stack to show” that the internet doesn’t have to operate this way. She concludes we don’t have to “demonize private activity while valorizing centralized surveillance in a way that’s often not critical.” We’re glad that a few stalwart tech companies, from Apple and its iPhone to Signal, refuse to cave on encryption. And we hope there are more, not fewer, such companies in the near future that refuse to expose their customers to hackers and government snooping. “We don’t want to be a single pine tree in the desert,” Whittaker says, adding she wants to “rewild that desert so a lot of pine trees can grow.” We’re all resigned to the need to go through security at high-profile sporting and cultural events, just as we do at the airport. The American Civil Liberties Union is raising the question – will that level of scrutiny be the new normal at the mall, at open-air tourist attractions, outdoor concerts, and just plain walking around town? The Department of Homeland Security (DHS) is investing in research and development to “assess soft targets and address security gaps” with new technology to track people in public places. It is funding SENTRY, the Soft Target Engineering to Neutralize the Threat Reality. SENTRY will combine artificial intelligence from the “integration of data from multiple sources,” which no doubt will include facial recognition scans of everyone in a given area to give them a “threat assessment.” We do not dismiss DHS’s concern. The world has no lack of violent people and our country is full of soft targets. Just hark back to the deranged shooter in 2017 who turned the Route 91 Harvest music festival in Las Vegas into a shooting gallery. He killed 60 people and wounded more than 400. A similar act by a terrorist backed by a malevolent state could inflict even greater casualties. But we agree with ACLU’s concern that such intense inspection of Americans going about their daily business could lead to the “airportization” of America, in which we are always in a high-security zone whenever we gather. ACLU writes that “security technology does not operate itself; people will be subject to the petty authority of some martinet guards who are constantly stopping them based on some AI-generated flag of suspicion.” We would add another concern. Could SENTRY be misused, just as FISA Section 702 and other surveillance authorities have been misused? What is to keep the government from accessing SENTRY data for warrantless political surveillance, whether against protestors or disfavored groups targeted by biased FBI agents? If this technology is to be deployed, guardrails are needed. PPSA seconds ACLU’s comment to the watchdog agency, the Privacy and Civil Liberties Oversight Board (PCLOB), that asks it to investigate AI-based programs as they develop. Congress should watch the results of PCLOB’s efforts and follow up with legal guardrails to prevent the misuse of SENTRY and similar technologies. Supreme Court Justice Oliver Wendell Holmes observed that anyone “who respects the spirit as well as the letter of the Fourth Amendment would be loath to believe that Congress intended to authorize one of its subordinate agencies to sweep all our traditions into the fire to direct fishing expeditions into private papers on the possibility that they may disclose evidence of crime.” A century after Justice Holmes delivered that warning, the U.S. Securities and Exchange Commission is doing just that. This agency is methodically sweeping all our traditions into the fire to direct fishing expeditions that treat every investor as a criminal suspect. The good news is that the constitutionality of the SEC’s program is on trial in a case now before a federal judge in Waco, Texas. Here’s the background: Historically, when the SEC has suspected someone of insider trading, it had to issue an investigative subpoena. Then in 2010, the market suffered the “flash crash” – a trillion-dollar decline caused by technical glitches that lasted for 36 minutes. The SEC responded to this technical glitch by proposing Rule 613, which established the Consolidated Audit Trail (CAT), a database that collects not just investors’ trades, but also their privately identifiable information. This “solution” had nothing to do with the crash, but it perfectly illustrates former Chicago Mayor Rahm Emmanuel’s dictum that “you never want a serious crisis to go to waste.” Rule 613 requires self-regulatory organizations, like private stock exchanges, to collect every detail about trades in securities on a U.S. exchange. It also includes confidential data on more than 100 million private investors, making it the largest database outside of the National Security Agency. This database includes investors’ names, dates of birth, taxpayer identification numbers, Social Security numbers, and more. Now two Texas investors, in affiliation with the National Center for Public Policy Research, are suing the SEC for this massive violation of privacy. Their lawsuit, represented by the New Civil Liberties Alliance, could be required reading for law students seeking to understand the application of our constitutional rights, beginning with the Fourth Amendment. This lawsuit makes the case:
The lawsuit makes a convincing case that the U.S. Supreme Court’s 2018 Carpenter decision – which held that the government violates the Fourth Amendment whenever it seeks a suspect’s cellphone location history without a warrant – should make this case against CAT a slam-dunk. After all, the plaintiffs assert that unlike the issue in Carpenter, “with Rule 613 SEC does not need an investigative predicate, much less a court order, to obtain and analyze private information, nor is the information limited to any particular person or time frame.” Even if a federal judge declares CAT to be unconstitutional, however, it will only strike down one of many intrusive violations of Americans’ financial privacy by federal agencies. These include a new requirement of all business owners to file “beneficial ownership” forms, for which any American business owner can face two years in prison for a clerical mistake, and the U.S. Treasury’s Financial Crimes Enforcement Networks snooping into Americans’ financial transactions with the coerced cooperation of 650 private financial institutions. Once the election is over, Congress should pass the “Protecting Investors' Personally Identifiable Information Act,” introduced by Sen. John Kennedy, (R-LA), and Rep. Barry Loudermilk, (R-Ga.), which would allow the SEC to obtain personally identifiable information only by requesting it on a case-by-case basis. As the risks of the SEC’s reckless program become clearer, more Members of Congress should embrace another Holmes dictum: “State interference is an evil, where it cannot be shown to be a good.” The Securities and Exchange Commission is tracking the 61 percent of Americans who buy and sell stocks, from the trades they make to their personal identifying information. Some 3,000 SEC bureaucrats now have ready access to this database containing every single stock in the United States in a database called the Consolidated Audit Trail. Marc Wheat of Advancing American Freedom in The Washington Examiner writes: “The database is a disaster for the privacy of millions of people. In terms of the amount of information collected, only the National Security Agency’s data-collection program is larger, and that database is not focused on people. What is worse, these types of databases are not secure. In 2016, hackers made off with over $4 million by trading on at least 157 nonpublic earnings releases from the SEC’s very own Electronic Data Gathering, Analysis, and Retrieval system. “A commission that cannot protect a filing system that processes 1.7 million filings every year cannot be trusted to maintain the security of what will likely become a 100 million data point database. It is only a matter of time before it is breached, leaking people’s personal information to nefarious actors.” Government Promises to Protect Personal Data While Collecting and Using Americans’ Personal Data10/21/2024
Digital data, especially when parsed through the analytical lens of AI, can detail almost every element of our personal lives, from our relationships to our location histories, to data about our health, financial stability, religious practices, and political beliefs and activities.
A new blog post from the White House details a Request for Information (RFI) from OMB’s Office of Information and Regulatory Affairs (OIRA) seeking to get its arms around this practice. The RFI seeks public input on “Federal agency collection, processing, maintenance, use, sharing, dissemination, and disposition of commercially available information (CAI) containing personally identifiable information (PII).” In plain language, the government is seeking to understand how agencies – from the FBI to the IRS, the Department of Homeland Security, and the Pentagon – collect and use our personal information scraped from our apps and sold by data brokers to agencies. This request for public input follows last year’s Executive Order 14110, which represented that “the Federal Government will ensure that the collection, use, and retention of data is lawful, is secure, and mitigates privacy and confidentiality risks.” What to make of this? On the one hand, we commend the White House and intelligence agencies for being proactive for once on understanding the privacy risks of the mass purchase of Americans’ data. On the other hand, we can’t shake out of our heads Ronald Reagan’s joke about the most terrifying words in the English language: “I’m from the government and I’m here to help.” The blog, written by OIRA administrator Richard L. Revesz, points out that procuring “CAI containing PII from third parties, such as data brokers, for use with AI and for other purposes, raises privacy concerns stemming from a lack of transparency with respect to the collection and processing of high volumes of potentially sensitive information.” Revesz is correct that AI elevates the privacy risks of data purchases. The government might take “additional steps to apply the framework of privacy law and policy to mitigate the risks exacerbated by new technology.” Until we have clear rules that expressly lay out how CAI is acquired and managed within the executive branch, you’ll forgive us for withholding our applause. This year’s “Policy Framework for Commercially Available Information” released by Director of National Intelligence Avril Haines, ordered all 18 intelligence agencies to devise safeguards “tailored to the sensitivity of the information” and produce an annual report on how each agency uses such data. It is hard to say if Haines’ directive represents a new awareness of the Orwellian potential of these technologies, or if they are political theater to head off legislative efforts at reform. Earlier this year, the U.S. House of Representatives passed the Fourth Amendment Is Not For Sale Act, which would subject purchased data to the same standard as any other personal information – a probable cause warrant. The Senate should do the same. The government’s recognition of the sensitivity of CAI and accompanying PII is certainly a step in the right direction. It is also clear that intelligence agencies have every intention of continuing to utilize this information for their own purposes, despite lofty proclamations and vague policy goals about Americans’ privacy. To quote Ronald Reagan again, when it comes to the promises of the intel community, we should “trust but verify.” The recent approval of the House Intelligence Committee’s annual intelligence policy bill sets up a critical moment for the ongoing debate over surveillance powers, particularly the controversial FISA Section 702. While the bill does not include a provision to narrow the definition of "electronic communication service providers" (ECSP), this issue will soon come to a head in the House-Senate conference. Rep. Jim Himes (D-CT) signaled his acceptance of Senate Intelligence Chair Mark Warner’s "technical fix," which would narrow the scope of the ECSP definition. Himes said the change “would be totally fine with me,” and that “I always believed that the language was overbroad in the initial amendment…” This change would prevent ordinary businesses—like coffee shops or small offices—from being forced to assist in government surveillance. While Himes expressed he would be "totally fine" with Warner’s proposal, the issue has yet to be fully debated or incorporated into House legislation. We’ve seen efforts at reform falter before, and the final outcome will be determined behind closed doors in the House-Senate conference, where transparency is sorely lacking. As we’ve previously noted, broadening the ECSP definition without clear limitations would create a “Make Everyone a Spy” law, enlisting small businesses into the surveillance apparatus. Moreover, the administration’s reassurance that the law will only be applied to specific providers, based on a classified FISA court decision, is insufficient. History shows that such promises often erode over time, allowing the intelligence community to expand its surveillance reach through legal loopholes. John Wiegmann, the new top lawyer for the Office of the Director of National Intelligence, also supported Warner’s. But as with everything, we want to see the changes in writing in the bill. The closed-room conference between the House and Senate is where these decisions will play out, but the lack of public scrutiny makes it a fraught process. Given past betrayals on surveillance reform, we have ample reason for anxiety. Privacy advocates must remain vigilant and press for real reforms that ensure no further expansion of surveillance powers. The House and Senate need to guarantee that any changes made truly limit the scope of ECSPs and protect Americans from warrantless data collection. PPSA will be monitoring this situation closely as it unfolds. The Project for Privacy and Surveillance Accountability recently submitted a series of FOIA requests to law enforcement and intelligence agencies seeking critical information on how the agencies handle data obtained through the use of cell-site simulators, also known as Stingrays or Dirtboxes, which impersonate cell towers and collect sensitive data from wireless devices. Specifically, PPSA submitted requests to DOJ, CIA, DHS, NSA, and ODNI. These requests focus on what happens after the government collects this data. As PPSA’s requests state, PPSA “seeks information on how, once the agency obtains information or data from a cell-site simulator, the information obtained is used.” We are particularly interested in learning about the agencies’ policies for data retention, usage, and deletion, especially for data collected from individuals who are not the target of surveillance. PPSA has long been concerned with the invasive nature of these surveillance tools, which capture not only targeted individuals' data but also data from anyone nearby. As we previously stated in a 2021 FOIA request, “this technology gives the government the ability to conduct sweeping dragnets of metadata, location, and even text messages from anyone within a geofenced area.” These FOIA requests specifically demand transparency about what happens after the government collects such data. We seek records regarding policies on data retention, use, and destruction, particularly for information unrelated to surveillance targets. As our requests state, “PPSA wishes to know what policies govern such use and what policies, if any, are in place to protect the civil liberties and privacy of those whose data might happen to get swept up in a cell-site simulator’s data collection activities.” As we previously highlighted, Stingrays represent a significant intrusion into personal privacy, and we are committed to holding the government accountable for its use of such tools. By pursuing these requests, we aim to inform the public about the scope and potential risks of the agencies’ surveillance activities, and to push for greater safeguards over Americans’ private information. PPSA will continue to push towards transparency, and we will keep the public informed of our efforts. The Cato Institute is challenging the FBI and Department of Justice in court to demand transparency regarding the government’s warrantless surveillance practices under Section 702 of the Foreign Intelligence Surveillance Act (FISA). The lawsuit, brought under the Freedom of Information Act (FOIA), seeks the release of records on how well the FBI is complying with restrictions placed on the use of this controversial program. Section 702 allows U.S. agencies to monitor communications between foreigners abroad, but it has also been used to capture the communications of Americans, leading to allegations of overreach and privacy violations. Despite bipartisan efforts in Congress to reform or even dismantle Section 702, the public has been kept in the dark about whether any meaningful changes have occurred. Cato has been stonewalled in its efforts to obtain information that could reveal the extent of this surveillance. As Cato Senior Fellow Patrick Eddington pointed out: “When the FBI stonewalls public records requests about a massive surveillance program that gobbles up billions of communications yearly — including yours and mine — it’s violating the law… A law its agents and managers are sworn to uphold.” This case is about more than just documents; it’s about shedding light on potential abuses of power and ensuring that the law protects ordinary citizens from unwarranted government surveillance. The lawsuit raises an essential question about the balance between national security and civil liberties. Without transparency, it's impossible to know whether surveillance programs are being misused or if they adequately protect Americans’ privacy. Cato’s case is a crucial step toward uncovering whether the FBI is following the legal limits placed on Section 702 or if it continues to overreach under the cover of secrecy. If successful, this case could force the government to reveal whether it is truly adhering to the law in its use of FISA's broad surveillance powers. At stake is the privacy of millions of Americans whose communications could be intercepted without their knowledge or consent. This case deserves attention from everyone who values privacy and accountability. PPSA is proud to support Cato’s efforts to push for a future where government overreach is kept in check and individual liberties are safeguarded. We look forward to further developments in this case. The Fourth Amendment of the U.S. Constitution requires authorities to obtain a probable cause warrant before entering an American’s property. But Pennsylvania knows better. The Keystone State has a law that permits Waterways Conservation Officers – in plain language, fish wardens – to enter private property without a warrant to enforce fishing laws.
Call it the fishing exception to the Fourth Amendment. Tim Thomas and his late wife Stephanie discovered this purported legal loophole in 2023 while at their home on Butler Lake in Susquehanna County. (Hat tip for this story to Dan King of the Institute for Justice.) Pennsylvania Waterways Conservation Officer Ty Moon terrified Stephanie by banging on her front door, entering the Thomases’ backyard and standing on the porch to bang on her back door. He then took pictures of the couple’s cabin, vehicle, and boat. No warrant needed. The next day, the Thomases had pulled over to the side of the road to pick flowers, only to be confronted by officer Moon, who jumped out his car and accused the couple of illegal fishing. They later received a citation accusing Tim of evading the officer and fishing without a license. The charges were dismissed. Undeterred, Moon surveilled these very dangerous people with binoculars on a stakeout. Thinking he saw more rods on a boat that were legally allowed, he tramped several times up and down the side of the Thomases’ property, each time walking past a window where Stephanie, who was battling Stage IV cancer, had settled into a bath. (See the Institute for Justice’s compelling video on the case here.) The officer again accused the couple of breaking the law. This case against the Thomases also collapsed in court. Now the Institute for Justice has filed a federal lawsuit against the Pennsylvania Fish and Boat Commission seeking to strike down this blatantly unconstitutional law. “You don’t lose your constitutional rights simply because you happen to live near a lake,” says Institute for Justice attorney John Wrench. “That’s why we’re challenging the Pennsylvania statute that authorizes these outrageous searches.” We could end this piece with puns about wardens fishing for a crime, or the same wardens having to face the scales of justice, or constitutional arguments that will be like shooting fish in a barrel. But we see two larger issues with serious implications arising from this case. The first is that lawmakers in a major American state could be so out of touch with the roots of the law that they thought that there could be a fishing exception to the Constitution’s Fourth Amendment. Second, if a fish warden can be this invasive and clueless, just imagine how dangerous federal agencies can be on cases where the stakes go well beyond a mere citation. Sen. Mike Lee (R-UT) is advancing his new Saving Privacy Act to protect Americans’ personal financial information from warrantless snooping by federal agencies.“The current system erodes the privacy rights of citizens, while doing little to effectively catch true financial criminals,” Sen. Lee said. The bill’s co-sponsor, Sen. Rick Scott (R-FL), added: “Big government has no place in law-abiding Americans’ personal finances. It is a massive overreach of the government and a gross violation of their privacy.”
Are these two senators paranoid? Or are they reacting to genuine “massive overreach” from a government that already illicitly spies on Americans’ personal finances? Consider what PPSA has reported in the last three years:
“Traditionally, Americans’ financial holdings are kept between them and their broker, not them, their broker, and a massive government database,” state auditors and treasurers wrote in a recent letter to House Speaker Mike Johnson. “The only exception has been legal investigations with a warrant.”
TRAC sucks in wire transfers within the United States between American citizens, as well as with those sending or receiving money from abroad. Sen. Wyden told The Wall Street Journal that TRAC lets the government “serve itself an all-you-can-eat buffet of Americans’ personal financial data while bypassing the normal protections for Americans’ privacy.”
Could that actually happen? It did across the border, when the Canadian government used emergency powers to debank truckers engaged in a political protest. At home, the tracking of Americans’ spending is a Fourth Amendment violation that inevitably leads to the degradation of the First Amendment.
Sen. Lee’s bill counters this financial surveillance state by repealing many of the reporting requirements of the Bank Secrecy Act. It also repeals the Corporate Transparency Act (which forces small businesses to reveal their ownership), closes the SEC’s database on Americans’ trades, prohibits the creation of a Central Bank Digital Currency, and requires congressional approval before any agency can create a database that collects personally identifiable information of U.S. citizens. Finally, Sen. Lee’s Saving Privacy Act would institute punishments for federal employees who release Americans’ protected financial information, while establishing a private right of action for Americans and financial institutions harmed when their privacy is compromised by the government. The Saving Privacy Act is a landmark bill that deserves to become the basis of debate and action in the next Congress. The FBI, which surveilled academics at the University of California, Berkeley, in the 1950s and 1960s, is now reaching out to a think tank on that campus for help in devising ways to break encryption and other privacy measures used by consumers and private social media companies.
In this task, the FBI is seeking advice from the Center for Security in Politics, founded by former Arizona governor and Homeland Security Secretary Janet Napolitano, to devise ways to access the contents of communications from apps and platforms. “We need to work with our private-sector partners to have a lawful-access solution for our garden-variety cases,” one FBI official at the event told ABC News. The FBI’s actions are in keeping with a growing global crackdown on encryption, highlighted by the recent arrest of Telegram founder Pavel Durov in France. We could take days trying to unravel this Gordian knot of ironies. Better to just quote Judge James C. Ho of the Fifth Circuit Court of Appeals, who wrote in a recent landmark opinion on geofence warrants that: “Hamstringing the government is the whole point of our Constitution.” In finding geofencing the data of large numbers of innocent people unconstitutional, Judge Ho noted that “our decision today is not costless. But our rights are priceless.” The FBI has a lot of tools to catch the drug dealer, the pornographer and the sex trafficker. After all, the Bureau has been doing that for decades. The best mission for the partnership between the FBI and the Center for Security in Politics would be to focus on the “lawful-access” part of their quest. With so many smart people in the room, surely they can invent new and effective ways to solve many crimes while honoring the Fourth Amendment. The U.S. Department of Justice is pioneering ever-more dismissive gestures in its quest to fob off lawful Freedom of Information Act (FOIA) requests seeking to shed light on government surveillance. One PPSA FOIA request, aimed at uncovering details about the DOJ's purchase of Americans’ commercially available data from third-party data brokers, sets a new record for unprofessionalism.
Until now, we had become used to the Catch-22 denials in which the government refuses to even conduct a search for responsive records with a Glomar response. This judge-made doctrine allows the withholding of requested information if it is deemed so sensitive that the government can neither confirm nor deny its existence. But when the government issues a Glomar response without first conducting a search, we can only ask: How could they know that if they haven’t even searched for the records? DOJ’s latest response that arrived this week, however, is a personal best. The DOJ’s response shows that it didn’t bother to even read our FOIA request. Our request sought records detailing the DOJ's acquisition of data on U.S. persons and businesses, including the amounts spent, the sources of the data, and the categories of information obtained. This request was clearly articulated and included a list of DOJ components likely to have the relevant records. Despite this clarity, DOJ responded by stating that the request did not sufficiently identify the records. DOJ's refusal to conduct a proper search appears to be based on a misinterpretation, either genuine or strategic, of our request. DOJ claimed an inability to identify the component responsible for handling a case based solely on the “name” of the case or organization. However, PPSA's request did not rely on any such identifiers. Instead, DOJ's response indicates that it may have resorted to a generic form letter to reject our request without actually reviewing its contents. Precedents like Miller v. Casey and Nation Magazine v. U.S. Customs Service establish that an agency must read requests “as drafted” and interpret them in a way that maximizes the likelihood of uncovering relevant documents. DOJ’s blanket dismissal is not just a bureaucratic oversight. It is an affront to the principles of openness and accountability that FOIA is designed to uphold. If the DOJ, the agency responsible for upholding the law, continues to disregard its legal obligations, it sets a dangerous precedent for all government agencies. The good news is that DOJ’s Office of Information Policy has now ordered staff to conduct a proper search in response to PPSA’s appeal, a directive that should have been unnecessary. It remains to be seen whether the DOJ will comply meaningfully or continue to obstruct … perhaps with another cookie-cutter Glomar response. How far might DOJ go to withhold basic information about its purchasing of Americans’ sensitive and personal information? In a Glomar response to one of our FOIA requests in 2023, DOJ came back with 40 redacted pages from a certain Mr. or Mrs. Blank. They gave us nothing but a sea of black on each page. The only unredacted line in the entire set of documents was: “Hope that’s helpful.” This latest response is just another sign that those on the other end of our FOIA requests are treating their responsibilities with flippancy. This is unfortunate because the American public deserves to know the extent to which our government is purchasing and warrantlessly accessing our most private information. Filing these requests and responding to non-responsive responses administratively and in court is laborious and at times frustrating work. But somebody has to do it – and PPSA will continue to hold the government accountable. The Texas Observer reports that the Texas Department of Public Safety (DPS) signed a 5-year, nearly $5.3 million contract for the Tangles surveillance tool, originally designed by former Israeli military officers to catch terrorists in the Middle East.
In its acquisition plan, DPS references the 2019 murder of 23 people at an El Paso Walmart, as well as shooting sprees in the Texas cities of Midland and Odessa. If Tangles surveillance stops the next mass shooter, that will be reason for all to celebrate. But Tangles can do much more than spot shooters on the verge of an attack (assuming it can actually do that). It uses artificial intelligence to scrape data from the open, deep, and dark web, combining a privacy-piercing profile of anyone it targets. Its WebLoc feature can track mobile devices – and therefore people – across a wide geofenced area. Unclear is how DPS will proceed now that the Fifth Circuit Court of Appeals in United States v. Jamarr Smith ruled that geofence warrants cannot be reconciled with the Fourth Amendment. If DPS does move forward, there will be nothing to keep the state’s warrantless access to personal data from migrating from searches for terrorists and mass shooters, to providing backdoor evidence in ordinary criminal cases, to buttressing cases with political, religious, and speech implications. As the great Texas writer Molly Ivins wrote: “Many a time freedom has been rolled back – and always for the same sorry reason: fear.” When we’re inside our car, we feel like we’re in our sanctuary. Only the shower is more private. Both are perfectly acceptable places to sing the Bee Gee’s Staying Alive without fear of retribution.
And yet the inside of your car is not as private as you might think. We’ve reported on the host of surveillance technologies built into the modern car – from tracking your movement and current location, to proposed microphones and cameras to prevent drunk driving, to seats that report your weight. All this data is transmitted and can be legally sold by data brokers to commercial interests as well as a host of government agencies. This data can also be misused by individuals, as when a woman going through divorce proceedings learned that her ex was stalking her by following the movements of her Mercedes. Now another way to track our behavior and movements is being added through a national plan announced by the U.S. Department of Transportation called “vehicle-to-everything” technology, or V2X. Kimberly Adams of marketplace.org reports that this technology, to be deployed on 50 percent of the National Highway System and 40 percent of the country’s intersections by 2031, will allow cars and trucks to “talk” to each other, coordinating to reduce the risk of collision. V2X will smooth out traffic in other ways, holding traffic lights green for emergency vehicles and sending out automatic alerts about icy roads. V2X is also yet one more way to collect a big bucket of data about Americans that can be purchased and warrantlessly accessed by federal intelligence and law enforcement agencies. Sens. Ron Wyden (D-OR) and Cynthia Lummis (R-WY), and Rep. Ro Khanna (D-CA), have addressed what government can do with car data under proposed legislation, “Closing the Warrantless Digital Car Search Loophole Act.” This bill would require law enforcement to obtain a warrant based on probable cause before searching data from any vehicle that does not require a commercial license. But the threat to privacy from V2X comes not just from cars that talk to each, but also from V2X’s highway infrastructure that enables this digital conversation. This addition to the rapid expansion of data collection of Americans is one more reason why the Senate should follow the example of the House and pass the Fourth Amendment Is Not For Sale Act, which would end the warrantless collection of Americans’ purchased data by the government. We can embrace technologies like V2X that can save lives, while at the same time making sure that the personal information about us it collects is not retained and allowed to be purchased by snoops, whether government agents or stalkers. The phrase “national security” harks back to the George Washington administration, but it wasn’t until the National Security Act of 1947 that the term was codified into law. This new law created the National Security Council, the Central Intelligence Agency, and much of the apparatus of what we today call the intelligence community. But the term itself – “national security” – was never defined.
What is national security? More importantly, what isn’t national security? Daniel Drezner, a Fletcher School of Law and Diplomacy professor, writes in Foreign Affairs that it was the Bush-era “war on terror” that put the expansion of the national security agenda into overdrive. Since then, he writes, the “national security bucket has grown into a trough.” The term has become a convenient catch-all for politicians to show elevated concern about the issues of the day. Drezner writes: “From climate change to ransomware to personal protective equipment to critical minerals to artificial intelligence, everything is national security now.” He adds to this list the Heritage Foundation’s Project 2025’s designation of big tech as a national security threat, and the 2020 National Security Strategy document, which says the same for “global food insecurity.” We would add to that the call by politicians in both parties to treat fentanyl as a matter of national security. While some of these issues are clearly relevant to national security, Drezner’s concern is the strategic fuzziness that comes about when everything is defined as a national security priority. He criticizes Washington’s tendency to “ratchet up” new issues like fentanyl distribution, without any old issues being removed to keep priorities few and urgent. For our part, PPSA has a related concern – the expansion of the national security agenda has a nasty side effect on Americans’ privacy. When a threat is identified as a matter of national security, it also becomes a justification for the warrantless surveillance of Americans. It is one thing for the intelligence community to use, for example, FISA Section 702 authority for the purpose for which Congress enacted it – the surveillance of foreign threats on foreign soil. For example, if fentanyl is a national security issue, then it is appropriate to surveil the Chinese labs that manufacture the drug and the Mexican cartels that smuggle it. But Section 702 can also be used to warrantlessly inspect the communications of Americans for a crime as a matter of national security. Evidence might also be warrantlessly extracted from the vast database of American communications, online searches, and location histories that federal agencies purchase from data brokers. So the surveillance state can now dig up evidence against Americans for prosecution in drug crimes, without these American defendants ever knowing how this evidence was developed – surely a fact relevant to their defense. As the concept of national security becomes fuzzier, so too do the boundaries of what “crimes” can be targeted by the government with warrantless surveillance. “Trafficking” in critical minerals? Climate change violations? Repeating alleged foreign “disinformation”? When Americans give intelligence and law enforcement agents a probable cause reason to investigate them, a warrant is appropriate. But the ever-expanding national security agenda presents a flexible pretext for the intelligence community to find ever more reason to set aside the Constitution and spy on Americans without a warrant. Drezner writes that “if everything is defined as national security, nothing is a national security priority.” True. And when everything is national security, everyone is subject to warrantless surveillance. U.S. intelligence agencies justify tens of thousands of warrantless backdoor searches of Americans’ communications by claiming an exception to the Fourth Amendment for “defensive” purposes.
In testimony to Congress, FBI Director Christopher Wray has said that such defensive searches are absolutely necessary to protect Americans in real time who may be potential victims of foreign intelligence agents or cyberattacks. On this basis, the FBI and other agencies every year conduct tens of thousands of warrantless “backdoor” searches of Americans’ communications with data extracted from programs authorized by FISA Section 702 – even though this program was enacted by Congress not to spy on Americans, but to authorize U.S. agencies to surveil foreign spies and terrorists located abroad. Noah Chauvin, Assistant Professor of Law at Widener University School of Law, in a 53-page paper neatly removes every leg of the government’s argument. He begins with the simple observation that there is no “defensive” exception in the Fourth Amendment. Indeed, an analogous claimed exception for “community caretaking” was rejected by the U.S. Supreme Court in the 2021 decision on Caniglia v. Strom, holding that the government could not enter a home without a warrant based on the simple, non-exigent claim that the police needed to check on the homeowner’s well-being. Whether for community caretaking or for surveillance, the “we are doing this for your own good” excuse does not override the Fourth Amendment. In surveillance, the lack of constitutional validity makes the government’s position “a political argument, not a legal one.” Chauvin adds: “It would be perverse to strip crime victims of the Fourth Amendment’s privacy protections – a person should not lose rights because they have been violated.” It is apparently on the basis of such a “defensive search,” for example, that the FBI violated the Fourth Amendment rights of Rep. Darin LaHood (R-Ill). In that case, the FBI was concerned that Rep. LaHood was being unknowingly targeted by a foreign power. If the FBI can secretly violate the rights of a prominent and respected Member of Congress, imagine how blithely it violates your rights. While making these sweeping claims of violating the Fourth Amendment to protect Americans, “the government has provided almost no public information about how these defensive backdoor searches work.” Chauvin adds: “The government has claimed it uses backdoor searches to identify victims of cyberattacks and foreign influence campaigns, but has not explained how it does so, saying only that backdoor searches have ‘contributed to’ or ‘played an important role in’ intelligence services.” Also unexplained is how the government identifies potential American victims, or why it searches for victims instead of potential perpetrators. Nor does it reveal its success rate at identifying potential victims and how that compares to traditional methods of investigation. Finally, Chauvin asks: “Would obtaining permission before querying a victim compromise the investigation?” It is a matter of settled law that any American can give informed consent to waive his or her Fourth Amendment rights. “It seems particularly likely,” Chauvin writes, “that would-be victims will grant the government permission to perform defensive backdoor searches.” One can easily imagine a long list of companies – from hospitals to cloud providers – that would grant such blanket permission. So why not just do that? Finally, Chauvin appeals to Congress not just to remedy this backdoor search loophole for Section 702. He proposes closing this loophole for Americans’ digital data that U.S. intelligence and law enforcement agencies purchase from third-party data brokers, as well as for Executive Order 12333, a non-statutory surveillance authority claimed by the executive branch. At the very least, Congress should demand answers to Chauvin’s questions about how defensive searches are used and how they work. He concludes, “the government’s policy preferences should never override Americans’ constitutional rights.” As the 2024 elections loom, legislative progress in Congress will likely come to a crawl before the end of meteorological summer. But some unfinished business deserves our attention, even if it should get pushed out to a lame duck session in late fall or to the agenda of the next Congress.
One is a bipartisan proposal now under review that would forbid federal government agencies from strong-arming technology companies into providing encryption keys to break open the private communications of their customers. “Efforts to give the government back-door access around encryption is no different than the government pressuring every locksmith and lock maker to give it an extra key to every home and apartment,” said Erik Jaffe, President of PPSA. Protecting encryption is one of the most important pro-privacy measures Congress could take up now. Millions of consumers have enjoyed end-to-end encryption, from Apple iPhone data to communications apps like Telegram, Signal, and WhatsApp. This makes their communications relatively invulnerable to being opened by an unauthorized person. The Department of Justice has long demanded that companies, Apple especially, provide the government with an encryption key to catch wrong-doers and terrorists. The reality is that encryption protects people from harm. Any encryption backdoor is bound to get out into the wild. Encryption protects the abused spouse from the abuser. It protects children from malicious misuse of their messages. Abroad, it protects dissidents from tyrants and journalists from murderous cartels. At home, it even protects the communications of law enforcement from criminals. The case for encryption is so strong the European Court of Human Rights rejected a Russian law that would have broken encryption because it would violate the human right to privacy. (Let us hope this ruling puts the breaks on recent measures in the UK and the EU to adopt similarly intrusive measures.) Yet the federal government continues to demand that private companies provide a key to their encryption. The State of Nevada’s attorney general went to court to try to force Meta to stop offering encrypted messages on Facebook Messenger on the theory that it will protect users under 18, despite the evidence that breaking encryption exposes children to threats. PPSA urges the House to draft strong legislation protecting encryption, either as a bill or as an amendment. It is time for the people’s representatives to get ahead of the jawboning demands of the government to coerce honest businesses into giving away their customers’ keys. PPSA Asks Supreme Court to Hear X Corp.’s Constitutional Case Against Surveillance Gag Orders7/10/2024
PPSA announced today the filing of an amicus brief asking the U.S. Supreme Court to take up a case in which X Corp., formerly Twitter, objects to surveillance and gag orders that violate the First Amendment and pose a threat to the Fourth and Sixth Amendments as well.
When many consumers think of their digital privacy, they think first of what’s on their computers and shared with others by text or email. But the complex, self-regulating network that is the internet is not so simple. Our online searches, texts, images, and emails – including sensitive, personal information about health, mental health, romances, and finances – are backed up on the “cloud,” including data centers like X Corp.’s that distribute storage and computing capacity. Therein lies the greatest vulnerability for government snooping. The growth of data centers is prolific, rising from 2,600 to 5,300 such centers in 2024. And with it, so have government demands for our data. When federal agencies – often without a warrant – seek to access Americans’ personal data, more often than not they go to the companies that store the data in places like these data centers. For years, this power involved large social media and telecom companies. The power of the government to extract data, already robust, increased exponentially with the reauthorization of FISA Section 702 in April, which included what many call the “Make Everyone a Spy Act.” This provision defines an electronic communication service provider as virtually any company that merely has access to equipment, like Wi-Fi and routers, that is used to transmit or store electronic communications. On top of that, the government then slaps the data center or service provider with a Non-Disclosure Order (NDO), a gag order that prevents the company from informing customers that their private information has been reviewed. One such company – X Corp. – has been pressing a constitutional challenge against this practice regarding a government demand for former President Trump’s account data. PPSA has joined in an amicus brief supporting X’s bid for certiorari, asking the Court to consider the constitutional objections to government conscription of companies that host consumers’ data as adjunct spies, while restraining their ability to speak out on this conscription. In the case of X, the government has seized the company’s records on customer communications and then slapped the company with an NDO to force it to shut up about it. The government claims this secrecy is needed to protect the investigation, even though the government itself has already publicized the details of its investigation. Whatever you think of Donald Trump, this is an Orwellian practice. PPSA’s amicus brief informed the Court that the gag order “makes a mockery of the First Amendment’s longstanding precedent governing prior restraints. And it will only become more frequent as third-party cloud storage becomes increasingly common for everything from business records to personal files to communications …” The brief informs the Court: “NDOs can be used to undermine other constitutionally protected rights” beyond the First Amendment. These rights include the short-circuiting of Fourth Amendment rights against warrantless searches and Sixth Amendment rights to a public trial in which a defendant can know the evidence against him. Partial solutions to these short-comings are winding their way through the legislative process. Sen. Mark Warner, Chairman of the Senate Intelligence Committee, introduced legislation to narrow the scope of businesses covered by the new, almost-universal dragooning of businesses large and small as government spies – though House Intelligence Chairman Mike Turner is opposing that reasonable provision. Last year, the House passed the NDO Fairness Act, which requires judicial review and limited disclosures for these restraints on speech and privacy. As partial solutions wend their way through Congress, this case presents a number of well-defined concerns best defined by the Supreme Court. PPSA today announced the filing of a lawsuit to compel the FBI to produce records about the possible use of FISA Section 702 authority – enacted by Congress to enable surveillance of foreign targets on foreign soil – for political surveillance of Americans at home.
Activists on the left and the right have long suspected the FBI uses surreptitious means to spy on lawful protests and speech. Those suspicions were confirmed when a FISA court decision released in 2022 revealed that government investigators had used Section 702 global database to surveil all 19,000 donors to a single Congressional campaign. Acting on this concern, PPSA submitted a FOIA request to the FBI in February seeking all records discussing the use of Section 702 or other FISA authorities to surveil, collect information related to, or otherwise investigate anyone who attended:
The FBI almost immediately responded to PPSA that our FOIA request “is not searchable” in the FBI’s “indices.” The response also informed us that the FBI “administratively closed” our request. The FBI did not dispute that PPSA’s FOIA request reasonably described the requested records. This should have, under the FOIA statute, triggered a search requirement, but the FBI ignored it. The self-serving excuse that limitations to the FBI’s Central Records System overlooks the plentiful databases and search methods at the fingertips of one of the world’s premier investigative organizations. After a fruitless appeal to the Department of Justice’s Office of Information Policy, exhausting any administrative remedy, PPSA is now suing in the U.S. District Court of the District of Columbia to compel the FBI to produce these documents. We’ll keep you informed of any major developments. “Curtilage” is a legal word that means the enclosed area around a home in which the occupant has an expectation of privacy. Within the zone of curtilage, the Fourth Amendment implications usually force law enforcement officers to obtain a warrant before they can enter. Where curtilage begins and ends has long been a matter of fine, Jesuitic distinctions, hotly contested in courts across the country.
Sometimes the boundaries are obvious. In a landmark case, the U.S. Supreme Court in 2021 held in Lange v. California that a police officer who followed a driver into his garage entered his curtilage. The officer had no right to do so without a warrant. PPSA was pleased to see the Court adopt logic similar to our amicus brief in Lange. So much for garages. Now what about doorknobs? Terrell McNeal Jr. of Mankato, Minnesota, was arrested after police obtained a probable cause warrant to enter his apartment and found controlled substances, cash, and guns. The evidence behind the warrant was derived from his doorknob. A police officer had earlier obtained a code from the apartment’s landlord to enter the structure’s interior communal space. He had proceeded to swab the doorknob of McNeal’s front door. It tested positive for two controlled substances. That was the basis of the warrant. The doorknob was tainted, to be sure. But that left a nagging legal question: Was the search warrant itself tainted by a violation of McNeal’s curtilage? A district court did not think so. It bought the prosecution’s argument that the door handle and lock were outside of McNeal’s home. A county prosecutor made this point on appeal: “If the court looks at the door itself, it prevents people from looking into the home. That doesn’t make the outside of the door curtilage.” Actually, it does, ruled the Minnesota Court of Appeals. On June 10, the appellate court found that officers have “no implied license to remove material from the door handle and lock for laboratory testing.” The court did distinguish this case from one in which a search warrant was obtained after a drug-sniffing dog found the aromatic traces of narcotics in the air in front of an apartment. But the officers in the McNeil case, the court ruled, “went a step further and collected a sample from a door handle and lock that were physically attached to and indivisible from appellant’s home.” The Minnesota Court of Appeals made the correct decision, voiding the conviction. As for McNeal, the authorities kept him in prison since his arrest more than two years ago, until the appellate court ruled in his favor. But at least the court recognized that swabbing any part of a home without a warrant is a violation of the Fourth Amendment. In the early 1920s revenue agents staked out a South Carolina home the agents suspected was being used as a distribution center for moonshine whiskey. The revenue agents were in luck. They saw a visitor arrive to receive a bottle from someone inside the house. The agents moved in. The son of the home’s owner, a man named Hester, realized that he was about to be arrested and sprinted with the bottle to a nearby car, picked up a gallon jug, and ran into an open field.
One of the agents fired a shot into the air, prompting Hester to toss the jug, which shattered. Hester then threw the bottle in the open field. Officers found a large fragment of the broken jug and the discarded bottle both contained moonshine whiskey. This was solid proof that moonshine was being sold. But was it admissible as evidence? After all, the revenue agents did not have a warrant. This case eventually wound its way to the Supreme Court. In 1924, a unanimous Court, presided over by Chief Justice (and former U.S. President) William Howard Taft, held that the Fourth Amendment did not apply to this evidence. Justice Oliver Wendell Holmes, writing the Court’s opinion, declared that “the special protection accorded by the Fourth Amendment to the people in their ‘persons, houses, papers and effects,’ is not extended to the open field.” This principle was later extended to exclude any garbage that a person throws away from Fourth Amendment protections. As strange as it may seem, this case about broken jugs and moonshine from the 1920s, Hester v. United States, provides the principle by which law enforcement officers freely help themselves to the information inside a discarded or lost cellphone – text messages, emails, bank records, phone calls, and images. We reported a case in 2022 in which a Virginia man was convicted of crimes based on police inspection of a cellphone he had left behind in a restaurant. That man’s attorney, Brandon Boxler, told the Daily Press of Newport News that “cellphones are different. They have massive storage capabilities. A search of a cellphone involves a much deeper invasion of privacy. The depth and breadth of personal and private information they contain was unimaginable in 1924.” In Riley v. California, the Supreme Court in 2018 upheld that a warrant was required to inspect the contents of a suspect’s cellphone. But the Hester rule still applies to discarded and lost phones. They are still subject to what Justice Holmes called the rules of the open field. The American Civil Liberties Union, ACLU Oregon, the Electronic Privacy Information Center, and other civil liberties organizations are challenging this doctrine before the Ninth Circuit in Hunt v. United States. They told the court that it should not use the same reasoning that has historically applied to garbage left out for collection and items discarded in a hotel wastepaper basket. “Our cell phones provide access to information comparable in quantity and breadth to what police might glean from a thorough search of a house,” ACLU said in a posted statement. “Unlike a house, though, a cell phone is relatively easy to lose. You carry it with you almost all the time. It can fall between seat cushions or slip out of a loose pocket. You might leave it at the check-out desk after making a purchase or forget it on the bus as you hasten to make your stop … It would be absurd to suggest that a person intends to open up their house for unrestrained searches by police whenever they drop their house key.” Yet that is the government position on lost and discarded cellphones. PPSA applauds and supports the ACLU and its partners for taking a strong stand on cellphone privacy. The logic of extending special protections to cellphones, which the Supreme Court has held contain the “privacies of life,” is obvious. It is the government’s position that tastes like something cooked up in a still. A report by The New York Time’s Vivian Wang in Beijing and one by Tech Policy’s Marwa Sayed in New York describes the twin strategies for surveilling a nation’s population, in the United States as well as in China.
Wang chronicles the move by China’s dictator, Xi Jinping, to round out the pervasive social media and facial recognition surveillance capability of the state by bringing back Mao-era human snitching. Wang writes that Xi wants local surveillance that is “more visible, more invasive, always on the lookout for real or perceived threats. Officers patrol apartment buildings listening for feuding neighbors. Officials recruit retirees playing chess outdoors as extra eyes and ears. In the workplace, employers are required to appoint ‘safety consultants’ who report regularly to the police.” Xi, Wang reports, explicitly links this new emphasis on human domestic surveillance to the era when “the party encouraged residents to ‘re-educate’ purported political enemies, through so-called struggle sessions where people were publicly insulted and humiliated …” Creating a society of snitches supports the vast network of social media surveillance, in which every “improper” message or text can be reviewed and flagged by AI. Chinese citizens are already followed everywhere by location beacons and a national network of surveillance cameras and facial recognition technology. Marwa Sayed writes about the strategy of technology surveillance contained in several bills in New York State. One bill in the state legislature would force the owners of driver-for-hire vehicles to install rear-facing cameras in their cars, presumably capturing private conversations by passengers. Another state bill would mandate surveillance cameras at racetracks to monitor human and equine traffic, watching over people in their leisure time. “Legislators seem to have decided that the cure to what ails us is a veritable panopticon of cameras that spares no one and reaches further and further into our private lives,” Sayed writes. She notes another measure before the New York City Council that would require the Department of Sanitation to install surveillance cameras to counter the insidious threat of people putting household trash into public litter baskets. Sayed writes: “As the ubiquity of cameras grows, so do the harms. Research shows that surveillance and the feeling it creates of constantly being watched leads to anxiety and paranoia. People may start to feel there is no point to personal privacy because you’ll be watched wherever you go. It makes us wary about taking risks and dampens our ability to interact with one another as social creatures.” Without quite meaning to, federal, state, and local authorities are merging the elements of a national surveillance system. This system draws on agencies’ purchases of our sensitive, personal information from data brokers, as well as increasingly integrated camera, facial recognition, and other surveillance networks. And don’t think that organized human snitching can’t come to these shores either. During World War One, the federal government authorized approved citizens to join neighborhood watch groups with badges inscribed with the words, “American Protection League – Secret Service.” At a time when Americans were sent to prison for opposing the war, the American Protection League kept tabs on neighbors, always on the watch out for anyone who seemed insufficiently enthusiastic about the war. Americans could be reported to the Department of Justice for listening to Beethoven on their phonographs or checking out books about German culture from the library. Today, large numbers of FBI and other government employees secretly “suggest” that social media companies remove posts that contain “disinformation.” They monitor social media to track posts of people, whether targeted by the FBI as traditional Catholics or observant Muslims, for signs of extremism. As world tension grows between the United States and China, Russia, Iran and North Korea, something like the American Protection League might be resurrected soon in response to a foreign policy crisis. Its digital ghost is already watching us. The surveillance state is hitting small businesses hard lately. If the “Make Everyone a Spy” provision weren’t enough, the Corporate Transparency Act (CTA) imposes sweeping disclosure requirements on “beneficial owners” of small businesses, with harsh punishments for mistakes on an official form.
After the National Small Business Association sued the Treasury Department, a federal court declared the CTA unconstitutional. It issued a scholarly opinion that explored the nuances of Congress’s power to regulate interstate commerce. Treasury appealed to the Eleventh Circuit. In our amicus brief, PPSA tells the Eleventh Circuit that the lower court got it right, but that there’s an easier way to resolve this case. We inform the court that the Fourth Amendment provides the “straightforward and resounding answer” that the CTA is unconstitutional. PPSA warns that the CTA’s database provisions pose an unprecedented threat to Americans’ privacy that are “even more disturbing” than the new rule’s disclosure requirements. We explain that the information collected from tens of millions of beneficial owners will be stored in what the government calls an “accurate, complete, and highly useful database” that can be searched by multiple federal agencies, no warrant required. And while the government claims this data will be used to catch tax cheats, the CTA says it will be used in conjunction with state and tribal authorities, who have no power to enforce federal tax laws. Creating such a database for warrantless inspection by the FBI, IRS, DEA, and Department of Homeland Security is obviously ripe for abuse. Our brief explains how this database could be used to identify owners of businesses with an ideological character – like political booksellers – and single out their investors for retaliation. This is not a far-fetched hypothetical. Many agencies, including the Treasury Department, have engaged in politically motivated financial investigations, documented in detail by the House Judiciary Committee. Our brief notes that the database will be so sophisticated that it should be evaluated under a U.S. Supreme Court precedent addressing high-tech surveillance, just as the Fourth Circuit did for Baltimore’s database-driven aerial surveillance program. And that precedent explains that surveillance tools can’t be used to undermine the sort of privacy that existed when the Fourth Amendment was adopted. We told the court: “This database thus has the sort of ‘depth, breadth, and comprehensive reach,’ that is simply incompatible with ‘preservation of that degree of privacy against government that existed when the Fourth Amendment was adopted.’” As pernicious as the database itself is, recent advances in technology make it even worse. With modern machine learning, seemingly innocuous personal details can be linked up in disturbing ways. For instance, researchers have known how to identify authors based on a collection of anonymous posts since 2022. PPSA points out that the government could identify authors with views it dislikes, see if they pop up in the beneficial owner database, and have multiple agencies launch pretextual investigations. Next, we address how advancing AI technology could make such surveillance even more potent, then urged the court not to “leave the public at the mercy of advancing technology,” but to preserve Founding-era levels of privacy despite the march of technology. Readers might notice a pattern of AI exacerbating existing privacy invasions, from mass facial recognition to drone surveillance to a proliferating body of databases. So far, the government has relied on the “special needs” exception. This rule allows the government to keep its own house in order, with the warrantless drug testing of schoolteachers and top-secret national security employees. But this authority is often abused, as we’ve noted previously. Our brief explains that this exception doesn’t even apply to information collected to identify crimes – which is exactly what the government claims the CTA is supposed to help with. But the struggle for constitutional rights and privacy remains multilayered. If the CTA remains struck down, the government will still be purchasing vast amounts of Americans’ personal information from shady “data brokers.” That’s why we applauded the House recently for passing the Fourth Amendment Is Not For Sale Act, and urge the Senate to do so as well. Now it is up to the Eleventh Circuit to protect the American people from an overbearing government, hungry to track our every move. |
Categories
All
|
RSS Feed