For a long time, cell site simulators, a.k.a. “Stingrays” made headlines on nearly a daily basis. Then they just kind of fell off the map.
L3Harris — the manufacturer of cell site simulators that commanded enough market share to see its flagship product become the victim of genericide — saw the writing on the wall and exited the market. Part of this was due to cell tech advances that made it more difficult to obtain the information these faux cell towers were meant to collect. Part of that was also Supreme Court precedent that made the tech inherently less popular with US law enforcement.
Riley raised questions about cell site simulator use by requiring warrants for cell phone searches. And spoofing a cell tower was definitely a search, as the devices forced every cell phone in the area to connect to the Stingray and cough up identifying info about the device. Carpenterarrived a few years later and made it clear long-term tracking via cell site location was no longer something covered by the Third Party Doctrine.
But the biggest contributor to the decline in Stingray device usage were the warrant requirements instituted by both federal and local law enforcement agencies. What used to be a Wild West free-for-all was now something that required judicial approval. Apparently, a lot of cops decided this tech they once claimed was so useful to investigations it couldn’t be discussed in open court was useless now that it was subject to oversight.
We’re seeing a bit of an anomaly here. Not only is the use of cell site simulators being discussed in open court, but the federal officers have been denied their unusual — and outrageous — request to basically go wardriving for a month in Akron, Ohio. Here’s This Week in Security with more details:
A U.S. magistrate judge last month denied to issue a search warrant allowing federal agents to snoop on the phones of “thousands of uninvolved, unsuspecting individuals” across Ohio in an effort to identify a suspected criminal’s device, a rare rebuke by a court blocking the use of a cell-site simulator.
In the ruling, the judge said the federal government wanted to deploy a cell-site simulator that would have allowed “access to the information of thousands of individuals in the Akron, Ohio area,” but refused the warrant on grounds that it would have allowed federal agents to “gain unbridled discretion to examine the movements of private citizens at all times for thirty days.”
The ruling [PDF] by the magistrate doesn’t name the federal agency seeking the warrant, nor does it give any details about the alleged criminal activity that might help narrow the list down. The rest of the docket remains sealed so it may be weeks, months, or never before we learn anything else about this incident.
Here’s what it does say about the events leading up to this severely deficient warrant:
On June 15, 2026, the government sought approval of a warrant for use of CCSS for up to 30 days, 24 hours a day, to identify the cellular device(s) used by a suspect involved in criminal activity in Akron, Ohio. The affidavit to the warrant application established probable cause to believe that a specific individual is using one or more unknown cellular devices in criminal activity. The affidavit also suggested that there is probable cause to believe that uncovering the identity of the cellular device(s) would unveil more evidence of criminal activity.
The problem is right there in the first sentence. The government appeared to think the only thing it had to do to satisfy the particularity requirements of the Fourth Amendment was to suggest it might limit this roving, 24/7 surveillance to a few areas in Akron.
Moreover, in an attachment to the warrant application, the government described five different locations at which a CCSS could be used to identify the suspect’s cellular device(s) “when the officers to whom it is directed have reason to believe that [the suspect] is present” and “in the vicinity of” the following locations:
the suspect’s residence; the suspect’s overnight location; the suspect’s daytime location; and two other densely populated locations the suspect frequently visited.
That’s wild. This is basically telling the court the government wants to force thousands of devices to connect to its cell site simulator at multiple locations for a period of 30 days. That the agency said it would “take no further investigative steps” until it had gathered enough info to make sure it had found its preferred suspect is hardly comforting. The fact that it claimed it would delete any irrelevant information (at an unspecified time) following its 30 days of wardriving doesn’t help much either.
The court says this is obviously impermissible under any interpretation of the Fourth Amendment, especially given Supreme Court precedent handed down in recent years. It also cites geofence warrants that have been recently rejected by magistrates for pretty much the same reason: wholesale surveillance of hundreds or thousands of people attempting to present itself as a legitimate search under the Fourth Amendment.
The court reminds the government that the Fourth Amendment says this about warrants:
[N]o Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
The court says this warrant is no better than the geofence warrant rejected by an Illinois federal court back in 2023: searching for a suspect by searching everyone officers encounter isn’t “particular,” and the use of warrant doesn’t make it more acceptable.
There, just as here, the proposed warrant allowed the government access to thousands of identifiers and location data in an undetermined geographic area. Id. at 715–16. The court found the CCSS [canvassing cell site simulator] “akin to a warrant application to search an entire apartment building—or an entire city block—where the government has probable cause only that evidence of a crime will be found in one specific apartment unit, for up to 30 days.”As that court recognized—and as this Court now concludes—the Fourth Amendment’s particularity requirement bars this sort of “rummaging” through the proverbial home.
That much should have been obvious to the investigators seeking to have this warrant approved. Either this was ignored in hopes investigators could slip one by the judge or the government thought this might somehow be more constitutional than a geofence warrant with the same parameters. Either way, the government was wrong.
Despite cops relying on Google location data more than cell tower dumps or Stingray devices these days, it’s clear they’re still relying on tech that has completely fallen out of favor over the past several years. I guess if you’ve already bought it, you may as well use it. Sunk cost meets diminishing returns. Fortunately for the Fourth Amendment, blowing the dust of a cell site simulator hasn’t changed the way courts view these warrants.
Frank Ssekamwa says the United States presented his country with an impossible choice. If it accepted the terms of a new health agreement, Uganda would have to give the U.S. access to the data of millions of his fellow citizens — a decision he worries would make their personal information more vulnerable to breaches and possible exploitation.
But if it refused, the East African nation would likely lose out on more than a billion dollars to address HIV, malaria, tuberculosis and other illnesses, even as its people face ongoing threats from Ebola and other deadly infectious diseases.
So, on Dec. 10, it agreed.
“If you take the deal, you’re going to be exploited. If you don’t take it, you’re going to die,” said Ssekamwa, an attorney and digital rights expert in Uganda. “It’s the essence of digital colonialism.”
Across Africa, countries have faced similar dilemmas as the U.S. has held a series of closed-door negotiations in which lifesaving aid has been conditioned on access to citizens’ health data. The negotiations come in the wake of the dismantling of the U.S. Agency for International Development, which — in contrast with the new contracts — provided billions of dollars in aid with few strings attached. Officials in Zambia, Zimbabwe and Ghana have been so outraged by the demands that they rejected the initial deals.
The demand to access health data is central to the Trump administration’s new America First Global Health Strategy, an openly transactional approach that seeks to leverage the desperate need for medical treatments abroad. Aid will now be given “in a way that directly benefits the American people and directly promotes our national interest,” Secretary of State Marco Rubio stated in September.
The State Department declined to publicly release global aid and data-sharing agreements it has signed with more than 30 countries as part of its new approach. But a ProPublica analysis of nine of the deals offers a window into the extensive U.S. demands for access to data — and the potential risks and vulnerabilities for the citizens of countries that have signed them. ProPublica also reviewed a data-sharing agreement struck with Uganda, which has not previously been reported; a data agreement with Kenya; six agreements over the sharing of pathogens that can cause pandemics that were made public by the State Department this week; generic templates of deals for sharing both data and pathogens that can cause pandemics; and an analysis of the documents the advocacy group Public Citizen shared exclusively with ProPublica.
ProPublica also consulted more than a dozen experts in data privacy and global health, including several with direct knowledge of U.S. policy who said that the insistent demands for data access and other resources as a condition of aid are unprecedented. Without seeing the full suite of agreements, they could not identify all vulnerabilities. But they spotted some red flags: The terms of the deals are vague and lack language standard in most data-sharing agreements that adequately limits what data is collected and how it can be used. That increases the risk that individuals’ personal data could be exposed, misused or commercialized without their consent.
In the Ugandan data deal, the U.S. will get direct, real-time access to nine of the nation’s health data systems for seven years, including the central repository that stores all of its health information, lab data, data collected by community health workers and, critically, its system for managing individuals’ electronic medical records.The agreement calls for the sharing of aggregated data with all personally identifiable information removed. It also says the data should be used for delivering and auditing healthcare services.
But lawyers and digital privacy experts argue that the deal raises questions about who will have access to the massive cache of health data and whether it could be inappropriately accessed and exploited.
Some expressed concern that, because it is possible to reverse-engineer data that has been anonymized, people with HIV, tuberculosis and other diseases could have their records exposed.
Stephanie Psaki, who served as the U.S. coordinator for global health security under President Joe Biden, described the Trump administration’s approach as a “blunt instrument of ‘just give me the login to your data systems.’”
“The U.S. would never agree to that,” she said, if the deal were offered in reverse.
In Uganda, the U.S. will provide up to $1.7 billion over five years for global health security and the treatment and prevention of deadly conditions such as malaria, tuberculosis, HIV and polio.In the past, the U.S. gave this aid without asking for direct benefits in return, saving an estimated 170,000 Ugandan lives per year.
While a significant investment, it is less than the U.S. previously spent in Uganda and will decrease every year of the agreement. By 2030, the African nation will receive 45% less global health funding than when Trump retook office, according to an analysis by Vincent Lin of Partners in Health, which provides healthcare in poor countries.
Several experts said there is broad support for some of the goals of the new plan for aid, including reducing African countries’ dependence on the U.S. for healthcare needs. But they worry the transactional nature of the approach could backfire by undermining trust or, in some cases, driving nations to reject deals altogether.
After withdrawing from the World Health Organization and losing access to its global network that tracks and combats disease outbreaks, the U.S. is attempting to obtain the information necessary to address potential pandemics through a patchwork of deals with individual countries. Each of the agreements ProPublica reviewed includes a section on responding to outbreaks. And some countries have signed separate pathogen-sharing agreements, which state that countries must “initiate sharing specimen(s) and related data” within five days of a U.S. request. The Trump administration is also planning unprecedented involvement of private companies to manage and process data.
The State Department told ProPublica that it needs access to the data to improve health outcomes in recipient countries and keep Americans safe. The new approach also requires countries to invest more in their own health systems in exchange for the aid, a promise many countries will likely struggle to fulfill. And, in some cases, including the deal with Uganda, it aims to boost local manufacturing through partnerships with American companies.
The State Department said it took multiple factors into account to ensure the required investments from other countries were “realistic and achievable.”
“The United States is investing billions of dollars in other countries’ health systems to fight infectious disease. In return, we expect governments to increase their own spending on health, so programs are sustainable and under genuine national ownership, not permanently financed by U.S. taxpayers. For the first time, both sides are putting skin in the game to ensure lasting impact,” a State Department spokesperson said in response to questions about the agreements.
In response to follow-up questions from ProPublica, spokesperson Tommy Pigott said the agreements “share only the same kinds of aggregated, de-identified data that has been shared and used for years in the fight against HIV/AIDS, malaria, tuberculosis, and other diseases. All data sharing is consistent with each country’s laws and approvals. No personally identifiable information is being received or shared by the United States government.”
Uganda’s Ministry of Health, Ministry of Foreign Affairs, Personal Data Protection Office and embassy in Washington, D.C., did not respond to questions for this article.
In the age of artificial intelligence, large health data sets have become so valuable they’ve been referred to as the new gold. The precise value of the health data of an entire nation is unclear, but it could be extremely valuable to AI-driven companies for training models.The industry of buying and selling such information troves is worth billions. And countries around the world have come to regard their citizens’ health records as national assets that deserve special protections and can confer economic and strategic advantages.
Yet the agreements, which are part of a strategy the State Department openly states is intended to make America “more prosperous” and “promote American health innovations,” provide no guarantee that Africans subject to them will have a say in what happens with their data or receive a fair share of its benefits. “Once companies get this data, the value is being accrued. But there’s no way for the [African] population to know how companies will use it,” said Jane Munga of the Carnegie Endowment for Intenational Peace, who has argued that the agreements may violate African privacy laws.
Africans have also expressed concern that they will not be able to access and benefit from medicines and vaccines developed from pathogen samples shared with the U.S. Five of the six specimen-sharing agreements reviewed by ProPublica state that, in the event that a medical product is developed primarily from a specimen from the country, the U.S. government “shall prioritize” a request from that government behind the needs of the U.S. Only one of the agreements, with Nigeria, commits the U.S. to facilitating “priority access” to — and the donation of — any medical products developed using the specimens.
The phenomenon of extracting information and samples from less-resourced populations and failing to credit and compensate them for their contributions to medical developments is well known enough to have several names, including “parachute science.” Just a few years ago, countries, including some in Africa, hosted COVID-19 vaccine trials, only to later struggle to access the shots they helped to develop.
Each agreement includes “benefit-sharing provisions,” the State Department said in response to questions.
After the Trump administration dismantled USAID, the world’s largest provider of humanitarian assistance, it also drastically reduced funding for international health work done by the Centers for Disease Control and Prevention and severely scaled back the President’s Emergency Plan for AIDS Relief, which combats HIV globally. In addition to withdrawing from the WHO, the U.S. removed itself from international negotiations over a pandemic agreement intended to affirm countries’ sovereign rights to their biological resources and ensure equitable access to medical interventions.
Brad Smith, an entrepreneur who served in the first Trump administration, is now in charge of creating the system that would rise from the ashes. Before joining this administration, Smith founded three companies with business models that rest in part on using data to reduce healthcare costs, including CareBridge, a home care provider that sold for a reported $2.7 billion in 2024. During the presidential transition that year, Smith led the government efficiency panel that would become Elon Musk’s Department of Government Efficiency. After Trump took office, he presided over some $67 billion in sweeping cuts to the Department of Health and Human Services before being brought on as an adviser to the State Department.
Although the humanitarian aid system had been largely dismantled, Congress required the executive branch to continue providing aid. So Smith and his team had to find new ways to get the funding to countries, ensure that it was being spent wisely and address potential pandemics — all without most of the international partners and staff the government had previously relied on to carry out this complex work.
A Rhodes scholar known for his intense work ethic, Smith threw himself into the effort. State Department staff fielded calls from him at all hours of the night to explain budget items on spreadsheets. Through his personal lawyer, Smith referred questions to the State Department.
One of the greatest challenges lay in the handling of health data. In the past, PEPFAR, the HIV program, built its own systems to handle anonymized data, separate from government health records — a setup that Trump administration officials and others have criticized as inefficient.
The America First plan proposed standardizing data collection and processing within countries. The Ugandan data agreement requires the country to provide the U.S. — and its contractors — with logins “or other secure access mechanisms” to directly enter the country’s data systems. The new approach, U.S. officials say, will enable the U.S. to continue auditing programs and track outbreaks.
The agreements ProPublica reviewed include statements about the U.S. government’s intent to ensure data security and say that the data is being accessed for the purposes of addressing diseases and auditing that work, but they leave open the possibility that sensitive information could be revealed, according to the data privacy experts ProPublica consulted.
At particular risk are countries that don’t have national data privacy laws, such as Liberia, whose memorandum of understanding requires “interlinked and interoperable” data systems for “surveillance, laboratory, response, health, environment, agriculture.” That country’s main health agreement doesn’t require the U.S. to limit the amount of data it takes to the least needed, a standard clause in U.S. contracts, according to Abdoul Jalil Djiberou Mahamadou, a recent postdoctoral fellow focusing on bioethics at Stanford University. (Neither Liberia nor the State Department has released the supplemental data-sharing agreement.) “Once data is breached, it’s nearly impossible to get it back,” Mahamadou added.
The Liberian government did not respond to a request for comment.
The Ugandan data-sharing agreement says it will comply with the laws of both nations and permits the sharing of “sensitive personal data” if the consent of individuals whose data is shared is obtained, there is a compelling public health emergency of international concern and it is the only way information can be provided in a “timely and accurate format.”
Ssekamwa, the digital rights expert who also founded and runs the African Centre for Digital Justice, said there are important questions that haven’t been answered by the Ugandan government.
“Does the U.S. have appropriate data protections? Can the systems provide anonymized data? Are they really up to that standard?” said Ssekamwa. “If I’m someone who has had health issues, can you deny me a visa because of the health issues I’m having?”
Psaki, the former global health security coordinator, worried about the haste with which the changes to data access are happening. “Even in the best of circumstances, you can’t go from having parallel data systems that were established over 20-plus years to finding some way to integrate those data systems in six months.”
Speed has been a hallmark of the America First global health effort. In September, just a month after Smith joined the State Department, it launched the strategy at an event co-sponsored by the U.S. Chamber of Commerce and five large pharmaceutical companies. By November, Smith was crisscrossing the African continent with a small team of negotiators, trying to persuade dignitaries to agree to deals.
The State Department said the deals were “negotiated in a thoughtful and strategic way over many months.”
On Dec. 4, Kenya became the first country to sign, during a triumphant celebration with Rubio and President William Ruto in Washington. Outcry over the agreement had already begun two days earlier, when a Kenyan activist named Nelson Amenya announced on the social platform X that he had seen a sample of the specimen-sharing agreement as well as a legal analysis that showed it would violate Kenyan law.
As a condition for receiving $1.6 billion in aid, the Kenyan government agreed to provide access to seven years’ worth of health records — two years longer than the U.S. would provide financial support.
Although the Kenyan data-sharing agreement states that the U.S. will take “all reasonable measures to protect the confidentiality of information” and abide by American and Kenyan laws, Amenya worried that wouldn’t be enough. “Every HIV test, TB diagnosis, malaria case – accessible to US officials,” he wrote in the post, which now has one million views. “Your medical records, your children’s health data – all exposed.”
A few days later, a Kenyan senator named Okiya Omtatah sued members of the Kenyan government over the agreement, arguing that it poses a threat to citizens’ constitutional right to privacy by “allowing broad foreign access to sensitive data.” A Kenyan nonprofit also sued, and more than 50 groups weighed in on their side, describing the document as giving the U.S. “excessive access” to African data and raising the possibility of serious human rights violations.
In court filings, the Kenyan government argued that it is obligated to achieve the “highest attainable standard of health” and that it is unable to do that on its own. After blocking the deal for months, in May, the Kenyan court temporarily allowed implementation of the agreement to proceed while it considers the case.
Since outrage bubbled up in Kenya, some other countries have negotiated shorter terms for sharing data and pandemic specimens, and have inserted additional protections, according to the Public Citizen analysis.
Revealing whether someone has had an abortion, mental health condition, substance use treatment or sexually transmitted disease can be devastating anywhere. In Africa, research has shown it can lead to discrimination and violence. And even when personal information has been removed, individuals in “anonymized” data can be reidentified using AI and other tools.
The Ugandan data-sharing agreement calls for the U.S. government to “promptly notify the Government of Uganda of any unauthorized access” in such cases and requires the parties to conduct a joint breach assessment and remediation plan afterward. But by that point, it may be too late, Ssekamwa fears. “Once the data gets out of Uganda, we are skeptical that the government of Uganda will actually have any power to control it,” he said.
The secrecy around both the negotiations and the agreements has raised further suspicions. The State Department has declined to share the agreements, telling ProPublica the agency will release them when negotiations with all partner governments are complete and describing its actions as “protecting sensitive negotiations—not ‘secrecy.’” In response to a public records request filed by ProPublica, the State Department said it planned to provide the documents in September 2027. The advocacy group Public Citizen recently filed suit against the federal government in an effort to obtain the documents.
“Why are they hiding the agreement if they think the terms are OK?” asked Bernard Okpi, a Nigerian lawyer who sued his government in March, alleging that the deal violates the country’s constitutional right to privacy and promotes religious discrimination by prioritizing funding for Christian faith-based health facilities. That suit is pending, and the Nigerian government did not respond to questions from ProPublica.
The State Department said that the agreement with Nigeria “was negotiated in connection with reforms the Nigerian government has made to prioritize protecting Christian populations from violence.”
The Trump administration says that its new global health strategy is designed to save lives and keep the U.S. — and the world — safe from disease outbreaks. But ultimately its hard-driving and secretive negotiations may work against those goals.
While the administration aspired to strike agreements with 50 nations, including the three countries that walked away from negotiations in part over concerns about data sharing, it has fallen far short of that number. (In Zambia, officials also balked at U.S. demands for critical minerals.) The loss of aid in those countries is already proving tobe devastating.
Despite the Trump administration’s stated goal of putting “America first,” the U.S. may feel the consequences of those failed negotiations, too, as mistrust compounds the loss of long-standing systems that provided care and responded to disease outbreaks.
“It’s in everyone’s interest to have a comprehensive approach to respond to an outbreak early,” said Psaki, who pointed to the quickly escalating number of Ebola cases in the Democratic Republic of Congo as evidence. While that country struck a healthcare deal with the U.S., five of the nine countries bordering it have not. “We need to get data and samples from all nine countries to collaborate effectively on that outbreak, and now we don’t have that.”
The State Department said the U.S. has responded swiftly to the outbreak and has provided over $270 million to the global fight against Ebola.
In Uganda, where people have also fallen sick and died from Ebola, Ssekamwa said that his country needs all the help that the healthcare deal can bring, including improved protection from outbreaks, but there needs to be more robust protection of people’s personal data.
“We are happy to benefit from the technological advancement and the fruits of big data,” he said. Instead, he said, “the U.S. has left so many gaps within the agreement, which can be exploited in their favor.”
The Trump administration’s continual trend towards maximum awfulness means that every report seems to be “I’ve got bad news and I’ve got worse news.” What was already bad has become even worse now that more of the administration’s actions have been exposed during court proceedings.
Last July, the Trump administration unilaterally decided ICE should have access to Medicaid data for the sole purpose of locating migrants to arrest and deport. That much was made clear by the administration itself, which said the data would give ICE officials better tools to discover “the location of aliens.” An agreement was reached with the Centers for Medicare and Medicaid Service by the DHS because of course that happened. The administration had already purged plenty of non-loyalists, which meant those remaining wouldn’t put up much of fight.
There was no legal basis for this demand, which is why the headline says “illegally.” If this was a legal request, we wouldn’t be seeing lawsuits challenging the sharing of this sensitive medical data because the law would already be settled. Specifically, ICE wanted access to Medicaid data that exposed “home addresses and ethnicities.” Not exactly subtle, but nothing ever is with this grotesque shotgun of an administration.
But this sharing was challenged in court, and that converts that bad news to worse news. Not only did ICE have access to information it wasn’t legally entitled to have, but its private contractors did too, as NPR reports:
After Medicaid officials improperly shared data about millions of people in January with immigration officials, ICE then shared that data with the data analytics firm Palantir, according to new court filings. Palantir operates an app called ELITE that is used by ICE agents to show the addresses of noncitizens who may be subject to deportation.
That revelation was made public in a motion filed Thursday by more than 20 Democratic attorneys general who sued the Trump administration last year over its data-sharing agreement between the Centers for Medicare and Medicaid Services and ICE.
Palantir’s thirst for data is constant. And it will take anything its government customers choose to give it, including information that has been obtained illegally.
Palantir issued a couple of statements in response to this reporting based on courtroom revelations in ongoing lawsuits.
First, it said that the data in question had been “purged.” That’s great if true, but this seems like something that needs verification before trust because who knows where else this data set ended up before court orders blocked the government from using this data. If you think only ICE was peeking into this illicitly obtained data, you’re awarding the government the good faith it not only hasn’t earned, but has spent pretty much every minute since Trump’s election actively destroying.
ICE’s surveillance tech contractor also said this:
Palantir provided the following statement to NPR: “Our customers control their own data and manage access to that data. When Palantir employees are granted access to a customer’s dataset, it is solely to help integrate and analyze that data — which is what our software does — not to store it or use it for our own purposes. Palantir can confirm that the dataset in question was purged pursuant to government instruction.”
Well… I’d like to believe this much in the same way I’d like to believe a system of checks and balances is capable of constraining a rogue regime, much less its private contractors who are not subject to these particular restraints.
I believe Palantir to the extent that its employees aren’t just surfing waves of incoming data for their own personal reasons, but I find it extremely difficult to believe that a belated “purge” has actually scrubbed the data and removed any ancillary… well, let’s call them “infections.” Without turning over evidence of this purge to the courts, it’s easy to say it’s all been handled, even if the only thing that happened what Palantir deleting the source CSVs (or whatever) from its system, which isn’t the same thing as stripping it from Palantir’s databases.
Another reason for high levels of skepticism is this: ICE somehow couldn’t stop itself from passing this illegally obtained data to Palantir despite (apparently) trying to comply with a court order.
In a court filing last week, the Justice Department said that CMS again inadvertently reshared with ICE the dataset with millions of names that CMS had first improperly shared with ICE in January. The government said the error occurred during an effort to share data from states not involved in the lawsuit.
You see the problem, right? Because not every state sued over this illegal data collection, ICE continues to collect data that should — at this point — be considered off-limits. The only reason it doesn’t is because some states (you know the ones) have decided they’ll do whatever it takes to ensure the administration gets to keep being openly racist.
Consequently, the data sets aren’t being sorted between racist/non-racist (or whatever the SORT term is), which means ICE continues to retain data it’s been ordered to delete and Palantir keeps getting handed data the government isn’t allowed to collect, much less distribute.
Then there’s the ultimate problem. No matter what’s happening here in the lower courts, the administration will continue to push for a resolution from the US Supreme Court. And the odds are about 6-3 that SCOTUS will say the government can do whatever it wants with whatever data it collects, ignoring years of precedent and administrative firewalls that are meant to protect US citizens (and residents) from being abused and surveilled by their government.
We — and plenty of others — have been warning that the global rush to mandate age verification wouldn’t stop at “let’s make sure kids can’t see porn” or even just “keep kids off of social media.” It would inevitably expand into treating anonymity and privacy tools themselves as the enemy. Australia is now proving that in real time: Its eSafety regulator has gone from checking whether porn sites gate their content to treating VPN use — one of the best tools people have for protecting their privacy online — as a compliance problem to be stamped out.
The correct term for age verification as it is implemented today is therefore identity verification. Given today’s internet infrastructure, it is unreasonable to assume that this information will not be shared through commercial agreements or with governments.
The consequence of introducing identity verification is therefore that freedom of information is restricted (you can no longer visit regulated websites anonymously) and that you can no longer post anonymously on social media. You cannot be certain that your criticism of the government will not be followed up by the authorities. You can no longer start a digital initiative on a social media platform aimed at gathering people to criticize an authority without facing a significant risk of consequences. Depending on the country you live in, this could even endanger your life. In its current form, social media identity verification removes important tools for activists in countries where criticizing those in power is dangerous.
Freedom of expression is threatened not only in a direct sense (you post something and then the police knock on your door), identity verification also creates a chilling effect. It becomes a cornerstone of censorship machinery in the sense that people begin to self-censor if they know that expressing opinions may have personal consequences. This is also something that changes over time. What is considered acceptable to post online is determined by whoever currently holds power. Different sides of politics often have different views on what constitutes harmful content. Just because what you post today is not considered inappropriate does not mean it will remain acceptable in the future.
Some can argue that they’re biased since they’re in the business of selling VPN service, though arguably, more age verification laws increase demand for VPNs. But, the reality is that as age verification laws spread, so too do the attacks on VPNs and the ridiculous and dangerous threats to somehow outlaw their usage.
The latest is in Australia, where their teen social media ban has been an abject failure. Have no fear, however, they’re going to just start targeting VPN usage. Of course, they’re not framing it as a response to the failure of their social media ban, but rather a response to adult content websites’ age verification being beaten by people using VPNs, because it’s always easier to start your attacks on privacy, security, and anonymity by blaming a more marginalized industry like adult content:
Nine in 10 of the most visited adult sites used by Australians now have age checks for users, according to the online safety regulator, but eSafety has said it will assess whether those sites are allowing users to bypass restrictions with virtual private networks (VPNs)….
But, of course, it’s not just about adult content. They’ll go after VPN usage for social media as well:
Similar to the expectations of the social media companies for the under-16s ban, eSafety said it was expected under the codes that sites “must take reasonable steps” to prevent workarounds like VPNs, and eSafety “will look at this when considering compliance”.
The sheer irony of an agency named “eSafety” claiming that VPN use was a “workaround” that must be blocked? VPNs provide way more safety than anything that the “eSafety” Commission has done regarding internet usage.
Age verification is surveillance. Full stop. And it’s increasingly being closely tied to law enforcement and governments. Tech policy expert Heather Burns recently pointed out that age verification providers were literally reporting people to law enforcement for the crime of… using an alternative OS. As she notes:
age verification providers now hold themselves to be delegated law enforcement and extensions of the judiciary, using the guise of age verification for child safety but for reasons which have nothing to do with it.
Iain Corby: Yeah, just briefly to add, I think there is a distinction here between when we just accept the parent’s word for the child’s age and when services need to get an independent verification of that age. We do know, this was mentioned earlier, that often, parents are complicit in helping their kids to access services which are age-limited when they shouldn’t be accessing those services. So, sometimes you will need to do an independent age verification rather than simply relying on a parental attestation. So, it’s sort of one step up from self-declaration, but it’s not an independent view of the age of that user.
So Australia is just confirming the point privacy folks have been screaming about for years: age verification is inherently an attack on privacy and security. It will absolutely be used to remove anonymity, decrease security, enhance law enforcement surveillance, and, as the last quote shows, diminish even parental decision-making regarding our children.
Age verification was never going to stop at the age gate. VPNs are just the next thing on the list. Other user empowerment tools (Tor? encrypted DNS?) will be next. There’s simply no version of this that ends with your privacy intact.
The 2026 FIFA World Cup is the largest sporting event in history. It’s also the most surveilled World Cup ever. If you’re visiting or traveling around host cities, then you and your face, behavior, movement and devices are being monitored by governments and private companies.
The U.S. government funneled more than US$1 billion to World Cup security to protect transit hubs, stadiums and surrounding areas; improve tactical operations such as bomb squads and SWAT teams; and add and upgrade equipment. It’s been a bonanza for the private sector.
Much of the investment in surveillance was done in the name of preventing harm from unauthorized drone use. Indeed, protecting against that threat is helping fuel the rapidly expanding government-private sector partnership in surveillance technology development and acquisition, which poses a different risk – to privacy.
As an attorney, author and educator who has worked for decades in privacy and surveillance, I’ve advised law enforcement about using drones and understand that security is critical to keeping people safe. The argument for security, however, is too often the catalyst to fund, develop and increase government surveillance capabilities that erode civil liberties, chill speech and undermine freedom of association.
And in my experience, surveillance-friendly policies and tech systems, once in place, rarely go away.
Cameras, drones and AI
The level of surveillance around this World Cup and changes in U.S. law and immigration policies prompted over 120 civil society groups – including Amnesty International and the American Civil Liberties Union – to issue a travel advisory. They warn that people visiting the U.S. may be subject to harms that breach the country’s legal human rights obligations.
That advisory lists risks of invasive social media screening, searches of electronic devices, racial profiling, arrest, detention, deportation and even death. European governments have issued travel advisories warning of surveillance and profiling as well.
AI-driven surveillance is playing a major role across the World Cup. The stadiums in host cities are equipped with facial recognition cameras that can collect and analyze facial biometrics of people in and around the stadiums. That data can be retained and used in future ways, unknown and uncontrolled by those whose biometric data has been collected.
The proliferation of facial recognition at events reflects a broader global trend normalizing biometric surveillance as these systems expand across cities.
Many states, like New York, are using federal funding for World Cup security to increase the number, capabilities and use of drones by law enforcement. Drones are remarkably capable and powerful surveillance tools easy to load with cameras, microphones, advanced sensors and weapons.
AI-supported autonomous software allows drones to monitor areas, track movement and gather intelligence. The drones can be powerful enough to scan entire cities or zoom in and read a milk carton from 60,000 feet (18,288 meters). They can carry technology that allows them to function like a cellphone tower, permitting law enforcement to determine your location or intercept texts and phone calls. Citywide drone networks could become the new normal.
Cameras are proliferating on the ground, as well. Robot dogs equipped with cameras are prowling in Dallas and New Jersey. And Seattle’s mayor decided to turn on and expand a major closed-circuit television system that had been previously shut down because of biometric privacy concerns.
While Seattle’s mayor said that the city is refining its policies to protect the surveillance data, numerous states and cities – with the aid of federal funding related to World Cup security — are rapidly expanding CCTV systems. Some CCTV systems were installed decades ago in major urban, high-tourism areas, like New York’s Times Square and the National Mall in Washington D.C.
Today, CCTV systems cover much greater areas, and with advances in artificial intelligence software, data analytics and increased technical capabilities, like thermal imaging, far more information can be gleaned from the captured data. CCTV systems can now detect, identify and classify objects, people and even people’s behavior. Government data fusion centers can merge that rich data with other intelligence and analyze it to identify individuals and reveal and predict patterns and behavior.
Surveillance traveling into and around the US
Proliferating government use of advanced AI surveillance tools is just one element of the privacy risk. The absence of comprehensive data privacy laws and changes in U.S. law and executive policies around immigration and gender make traveling into and around the United States a security, safety and privacy risk.
Also, President Donald Trump issued an executive order around gender on Jan. 20, 2025, that mandates federal agencies only recognize male and female sex markers on IDs. European nations, including Germany, have warned their transgender and nonbinary citizens that they may be denied entry to the U.S. because of the directive.
Collectively, these changes affect travel logistics, documentation requirements and border crossings.
What happens after the games?
The real test is what happens after the World Cup ends and visitors go home. There is little oversight or governance around these federally funded, public-private surveillance tech partnerships. It’s difficult for the public to determine what data is being collected, how that data is being used, shared and analyzed, and what will happen to these systems, partnerships and data when the final match concludes.
Federal, state and local legislators have an opportunity to address much of this by creating data privacy and AI systems compliance safeguards and requiring transparency, but in my view, governance efforts to date don’t bode well.
Anne Toomey McKenna is Affiliated Faculty Member at the Institute for Computational and Data Sciences, Penn State
It’s no secret ICE officers are using their phones and their tech toys to do way more than they’ll openly admit to doing. Tech tools that can be abused will be abused. And ICE has plenty of those, including an app that’s supposed to be used for “verification” of migrant status, but is just facial recognition tied to whatever other information ICE has access to.
The cameras come out and the harassment begins, as detailed here in this NPR report. Shortly after Portland, Maine resident Xenia Pantos stopped her car to observe some ICE activity in her neighborhood, their spouse, Carly Williams got a call from a blocked number. The caller identified himself as calling from the Department of Homeland Security.
Williams said the caller asked if anyone else drives her vehicle. When Williams mentioned her spouse sometimes did, the caller asked Williams if she knew her spouse had stopped at an incident that morning.
“What he basically said was, ‘You should let her know to not do that anymore because people who are doing that type of thing are getting added to a domestic terrorist watch list,'” Williams recalled in an interview with NPR.
ICE continues to deny it targets anti-ICE protesters with its surveillance tools. According to the report, it has “repeatedly denied” utilizing its tools and databases to find out more about those who protest or observe its anti-migrant efforts.
Rep. Lou Correa, D-Calif., cited a well-circulated clip of an ICE agent in Portland, Maine, telling a person videotaping that she would be added to a “nice little database.”
“I can’t speak for that individual,” said Todd Lyons, who serves as acting director of ICE. “But I can assure you that there is no database that’s tracking United States citizens.”
Lyons doubled down on his denials about the database’s existence during a Senate hearing Thursday. When asked if ICE is giving protester information to any other agency, Lyons said: “We do not.”
That’s what Todd Lyons said in February. And it’s definitely not true. ICE has a database that is definitely capable of “tracking American citizens,” because it has access to plenty of law enforcement databases filled with information about American citizens. One needs to look no further than the heat it has drawn by asking local law enforcement to perform searches of things like Flock’s ALPR databases on its behalf.
And it’s definitely not true because the same Todd Lyons said as much in a written response [PDF] to congressional queries that has only recently been made public.
Lyons in February: “There is no database that’s tracking United States citizens.”
Lyons in April: “Well… except for this one.”
Your letter asks what specific personal information DHS officers collect. ICE collects information to identify the person(s) with whom the officer or agent is engaging. During these interactions, a variety of data may be collected by ICE law enforcement officers to enforce federal immigration and criminal law. ICE collects essential biographic and biometric information and situational details required to support criminal investigations, safety, and immigration concerns.
If individuals who interact with ICE officers are not arrested or detained, any information collected during those encounters is maintained consistent with applicable law and DHS and ICE policies and is treated as an official government record.
That sounds like a database is being created and maintained — one that deals solely with people who are not targets of immigration enforcement effort. And most of those people would be (1) US citizens and (2) protesters and observers engaging with ICE officers.
Further down in the letter, Lyons offers up another phrase that sounds like a denial, but really isn’t:
DHS is not creating or maintaining a separate, standalone database for individuals encountered that haven’t been arrested or detained.
That would mean something if no information was collected on these people. But Lyons has already stated that officers collect this information. If DHS is not “creating or maintaining a separate database,” that only means exactly what that says. However, it does not mean DHS is not collecting and storing information about people ICE officers “encounter” who are not “arrested or detained.”
Even if all applicable laws and retention standards are being followed (and DHS has given us little reason to believe it follows laws and standards), this information is still being collected, stored, and — because it’s there — accessed by federal officers.
And even if we choose to believe Lyons’ dissembling, we’re still left with the fact that people identifying themselves as federal employees are calling up citizens who’ve done nothing more than exercise their First Amendment rights and threatening them with being added to government databases. So, even if Lyons ain’t lying, the people who worked for him (until he stepped down) aren’t doing what Lyons thinks they’re doing. They’re doing the other thing: collecting information on protesters and observers for the sole reason of keeping an eye on them, if not actually tracking them down to harass them.
Section 702 was one of the surveillance programs Ed Snowden exposed in 2013 — and even after the exposure, the NSA has continued abusing it to spy on Americans.
It’s the tool that lets the NSA collect communications to and from foreign “targets” — including any American on the other end of those communications, who the NSA is technically not supposed to surveil. It used to be worse. It used to include any communications “about” those targets (which made it very broad) but that was stripped out a few years ago, thankfully. Still, a ton of communications are collected under this program, including communications by and to Americans. The NSA then keeps all those communications, and so-called “backdoor searches” allowed the FBI to query those communications, meaning that even though the NSA has no authority to spy on Americans, the tool is used all the time to spy on Americans.
There was a brief period when Republicans were against it, when they thought that Democrats were using the authority to spy on them, but they quickly seemed to forget that once Trump was back in power, because of course they did.
Every single time it comes up for renewal, Congress dithers and frets, and we hear from the authoritarians in the government (across both parties) about how absolutely necessary it is to keep you safe from terrorists. That’s never been true. They never present any actual evidence for that claim. Just a lot of “trust us or you’ll be sorry.” And every time it comes up for renewal, and reformers push for a discussion on stopping its abuses, we’re told “no time for that, we must renew it, and we can debate reforms afterwards.” But no debate ever comes. They just wait until the next renewal, and we go through the same dance all over again.
But on Friday… the 702 authority expired. And the world hasn’t ended. Amusingly, this is almost entirely Trump’s own doing. It started with his decision to put Bill Pulte (who has zero experience in intelligence and is most famous for abusing his authority to go after Trump’s enemies) as the acting Director of National Intelligence. That caused Democrats to realize that if Pulte was abusing his position as director of the Federal Housing Finance Agency to investigate anyone he pleased, imagine what shenanigans he’d pull off with 702 powers. And so they blocked any further discussion on 702, and even got a few Republicans to go along with them. Hell, even Senate Majority Leader John Thune worried about how Pulte would “weaponize” 702.
That’s Trump posting to his personal emo blog Truth Social:
A few Dumocrats are against FISA, with or without Bill Pulte going to DNI, as Acting. What kind of deal is that. Besides, I’m against FISA if it doesn’t come with The Save America Act (Full version!) firmly attached to it. MAKE AMERICA GREAT AGAIN! Thank you for your attention to this matter. President DONALD J. TRUMP
Except the SAVE America Act, which serves no purpose other than to suppress voting, just doesn’t have the votes. So tying it to FISA renewal, which was already on shaky grounds, means they don’t have the votes for either.
The self-proclaimed ultimate dealmaker managed to kill the surveillance program his allies love by overplaying a weak hand. The intel community’s sky-is-falling routine has been exposed as the theater it’s always been. Congress should leave this one expired.
President Trump’s highly politicized appointment of an entirely unqualified acting Director of National Intelligence (DNI) underscores why the government’s warrantless mass spying power must be reformed.
Congress now faces a deadline of Friday, June 12 to reauthorize Section 702 of the Foreign Intelligence Surveillance Act, an unconstitutional program rife with problems, loopholes, and compliance issues. Section 702 allows the National Security Agency to collect communications from targets overseas – including communications with Americans in the U.S. – and stores them in massive databases. The NSA then allows other agencies, including the Federal Bureau of Investigation, to access untold amounts of that information.
Under current practice, the FBI can query and even read the U.S. side of that communication without a warrant. What’s more, victims won’t even know and have very few ways of finding out that their communications have been surveilled. EFF and other civil liberties advocates have been trying for years to know how data collected through Section 702 is used in domestic investigations and prosecutions.
Our advocacy to reform Section 702 has been consistent across administrations, including when the federal Intelligence Community was run by people with experience in the relevant agencies. In fact, the 2004 law creating the position of DNI – which coordinates America’s 18 spy agencies – requires those who hold it to have “extensive national security expertise.”
“William has deep experience managing the most sensitive matters in America, the safety and soundness of the Markets, and over 10 Trillion Dollars at Fannie Mae/Freddie Mac, a substantial increase from where it was just 12 months ago,” Trump wrote on his Truth Social platform.
Because Trump named him acting DNI, Pulte isn’t subject to Senate confirmation. And under the Vacancies Act, Pulte could remain in the role for about seven months.
This is particularly concerning because of Pulte’s history of using private information held by the government as a political weapon. In his FHFA role, he has accused several of the President’s political foes and targets – including New York State Attorney General Letitia James, U.S. Sen. Adam Schiff, D-Calif., and Federal Reserve governor Lisa Cook – of mortgage fraud based on private data held by his agency.
All these targets and others have denied wrongdoing. A federal criminal complaint filed against James in Virginia imploded after a judge found prosecutor Lindsey Halligan had been unlawfully appointed, and prosecutors twice failed to convince a grand jury to indict James. Pulte’s accusations against Schiff, Cook, and others have not led to criminal charges.
Pulte isn’t a qualified intelligence administrator. He does, however, seem to be unquestioningly loyal to President Trump and willing to use his position to attack and smear the President’s political foes. As acting DNI, Pulte would have access to every scrap of classified information the Intelligence Community holds, and under Section 702, that includes massive amounts of information about Americans.
Even lawmakers who are typically friendly to the intelligence community acknowledge that this is a disaster in the making. U.S. Sen. Mark Warner, D-Va., who is the Senate Intelligence Committee’s ranking Democrat, told NPR that Pulte has “no experience in the military, no experience in Congress, no experience in the intel community or law enforcement” and was chosen because he is “100% loyal to doing anything and everything President Trump demands.”
And Senate Majority Leader John Thune, R-S.D., told reporters “we don’t need a weaponized” national intelligence director. Asked about fears that Pulte might pursue Trump’s political opponents, Thune said: “We need professionals there.”
Congress already has had trouble reauthorizing Section 702 as Freedom Caucus Republicans and many Democrats joined forces to demand reforms including the common-sense requirement that federal agencies get a probable cause warrant from a judge before searching any data involving Americans. Pulte’s appointment exemplifies why no administration should have the power granted by Section 702 without the independent judicial review required in seeking a warrant.
There are two major reasons that the U.S. doesn’t pass an internet-era privacy law or regulate data brokers despite a parade of dangerous scandals. One, lobbied by a vast web of interconnected industries with unlimited budgets, Congress is too corrupt to do its job. Two, the U.S. government is disincentivized to do anything because it exploits this privacy dysfunction to dodge domestic surveillance warrants.
If we imposed safeguards on consumer data, everybody from app makers to telecoms would make billions less per quarter. So our corrupt lawmakers pretend the vast human harms of our greed are a distant and unavoidable externality (unless the privacy issues involve some kid tracking rich people on their planes, of course, in which case Congress moves with a haste that would break the sound barrier).
I’ve warned about this for the last decade here at Techdirt, and the check is coming due. The Pentagon is steadily coming to realize that enemies are using location data purchased from unregulated data brokers to target and kill U.S. troops overseas:
Poor Ron Wyden. The guy has been warning about this outcome for longer than Techdirt, and his reward is generally an apathetic congressional body too corrupted by greed to function.
This should surprise absolutely nobody.
Two years ago, Wired released an excellent report documenting how it was relatively trivial to buy the sensitive and detailed movement data of U.S. military and intelligence workers as they moved around Germany. And for much of the past decade cellular providers had been found to be collecting user movement data, selling it, and either not telling consumers or outright lying about it.
If foreign governments can’t get your sensitive location data from a litany of apps that track your every movement, they can get it from data brokers or the wireless carriers themselves.
When the FCC tried to fine wireless carriers like AT&T for spying on and monetizing consumer movements, the fines were vacated by Trump’s Fifth Circuit appeals court. Wyden had previously revealed how right wing extremists were able to easily purchase the location data of abortion clinic visitors and then target them with dangerous health care disinformation. The congressional response: bupkis.
It’s not subtle: the U.S. is too corrupt to function. Instead of fixing that problem, Republicans, “free market” Libertarians, and many centrist Democrats spend most of their time figuring out new ways to lobotomize our regulators, pre-empt meaningful privacy legislation, and completely defang what’s left of corporate oversight. You know, because we just love free market innovation so much.
In his latest letter to the Pentagon, Wyden once again makes the case that the ad tech industry, as currently formulated, poses a direct national security threat:
“Commercial location data can be used to identify where U.S. troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes,” the letter warned. Wyden said in a statement that it was time to “start treating the adtech industry as a national security threat.”
Of course, it’s not just the ad industry that poses a national security threat, it’s corruption. It’s the mindless deregulation of industry by bad faith actors. It’s lax government privacy and security oversight of private companies (and their executives). It’s regulatory capture at the hands of corrupt, weird zealots. And it’s a government obsessed with hyper-scaled domestic surveillance with no meaningful guardrails.
We’ve talked a lot about how Americans have somehow accepted the fact that our voice networks are now saturated with scammers, fraudsters, and robocallers (no, that’s not something that happens in well run, functionally regulated countries).
I’ve also explained for years how the U.S. government solutions to the problems are usually ineffective because they’re endlessly trying to create rules (or undermine existing ones) to carve out exceptions for big “legitimate corporations,” which routinely engage in the same sleazy behavior as scammers.
Regulatory capture and corruption means that you wind up with a lot of performative solutions that sound good, but don’t fix anything. And some of the progress we had made on robocalls is being undermined by the Trump administration’s brutal assault on the federal regulatory state, something that still, somehow, isn’t getting enough public and press attention.
Now the Trump administration is cooking up a new “fix” that once again isn’t likely to fix the robocall problem (because our consumer protection regulators don’t function and the Trump administration doesn’t actually care about the subject anyway), but is likely to introduce all manner of new privacy and surveillance headaches. If it’s even implemented.
In late April, the Trump FCC announced it was considering the development of new “Know Your Customer” rules requiring that the buyer of any new phone present a government ID, a physical address, a full legal name, and an existing phone number at the point of sale. This has raised eyebrows both among activists and telecom industry lawyers, albeit for understandably different reasons.
“We must bring meaningful robocall relief to consumers. The FCC is attacking the problem of illegal robocalls at every point in the call path in order to help consumers and restore trust in America’s voice networks. These proposals set the stage for significant advancement toward those goals by aiming to get providers to take accountability and step up their game in our shared battle against illegal robocalls.”
Telecom lawyers are nervous because the rules propose a $2,500 penalty, per call, per carrier, in a country that sees around 4.2 billion robocalls per month. So yeah, in a theoretical country where we actually had functioning consumer protections this would be quite a shift.
But accountability requires consumer protection enforcement, and this is Brendan Carr. A guy who generally doesn’t believe in holding major corporations accountable for literally anything. And who believes in defanging the federal regulatory state. It’s once again this interesting intersection between the Trump administration’s claims, and their very unsubtle effort to lobotomize government.
Which is to say I’m not even sure this proposal passes, much less sees any enforcement. And if it does pass, and does get enforced, it likely won’t actually help stop robocalls, because that would require a government willing to be tough on the biggest telecom giants which have historically not done enough to police fraud on their networks (at points because they were profiting from the fraud).
So what is Brendan Carr actually thinking? Like all dutiful autocrats, he’s thinking about his administration’s own power, and he’s thinking about surveillance.
There are, of course, numerous instances where you might want legal but covert ownership of a cell phone (a refugee seeking government punishment, a domestic abuse victim fleeing an abusive relationship, a journalist trying to protect a source identity, an activist planning a demonstration). Reclaim the Net is particularly concerned on the restrictions impacting the prepaid cell phone market:
“The real privacy stakes sit in the proposal’s section on prepaid service. Right now, you can pay cash for a prepaid phone and SIM card without showing identification. Journalists use prepaid phones to protect sources, domestic violence survivors use them to avoid being traced, and whistleblowers, activists, or anyone with a reason to separate phone activity from legal identity relies on this.”
So yeah, if Brendan Carr, a censorial autocratic zealot with a history of disdain for corporate accountability and consumer protection, is suddenly pitching you a quick and easy solution for a complicated consumer-facing issue, you should probably raise a skeptical eyebrow. Especially if you’re a journalist.