While it tends to get buried by the press, one thing is very true: the U.S. is too corrupt to pass a federal privacy law. For as long as the internet has existed, policymakers have prioritized making money over the common good and public safety. The end result is exactly what you’d expect: a steady parade of scandals that get more and more dangerous as the scope and scale of mindless data collection expands.
Instead of passing new, better, smarter privacy laws for the internet era, we’re instead usually focused on weakening the ones we already have. Or prioritizing the interests of the wealthy. Like recently, when Congress included language in the Federal Aviation Administration reauthorization bill that made it harder than ever for the public to track private jet travel.
In Illinois, Democratic Governor J.B. Pritzker has also signed off on a new privacy bill that also takes things in the wrong direction. SB2979 significantly curbs the penalties corporations face for improperly collecting and using fingerprints and other biometric data from workers and consumers.
The law reverses a 2023 Illinois Supreme Court ruling holding companies liable for each instance of privacy abuses related to the same data set. It also reverses a separate state court decision that gave impacted employees a five year window to sue over violations, instead of the one year window corporations preferred.
The U.S. is awash in privacy scandals because corporations and executives aren’t afraid of the penalties of lax security and flimsy privacy standards. They view small class actions or fines — which are immensely disproportionate to the money made from abuses — as simply the cost of doing business. It’s why a company like T-Mobile can be hacked eight times in five years and never learn its lesson.
Meaningful, well crafted privacy laws (not that we’ve seen many of those in recent years) empower workers and consumers, and restore faith in markets. But instead of meaningful reform, there’s no shortage of well-lobbied politicians dedicated to taking things the wrong direction, who are then absolutely nowhere to be found when the real-world harms arrive.
For a long time we’ve been pointing out just how dangerous it is to turn over school discipline problems to cops. Sure, there are reasons schools might need a police response to an incident, but putting cops on staff has allowed administrators to abdicate their duties and turn incidents that could be resolved by educators and parents into arrests, criminal charges, and — as is always the case when cops are involved — acts of brutality.
Cops in schools have arrested kids as young as five years old. In doing so, the only perceived obstacle is the tiny bodies, which are incapable of wearing handcuffs “properly.” Littering campuses with cops also means arresting parents for things their children have done, even when it’s nothing more than the normal creative expression expected from kids, like deploying finger guns or drawing a picture of a “bomb.”
When you turn discipline over to people who only see things in terms of criminal and non-criminal, problems arise. And when you turn this over to people in law enforcement, you also get the unadvertised add-ons: biased policing, casual violence, and a general disrespect for anyone who isn’t a cop.
It’s the biased policing that’s got the attention of two advocacy groups, who are now asking the federal government to investigate the use of “school resource officers” in Rockford, Illinois. As Jennifer Smith Richards and Jodi S. Cohen report for ProPublica, there’s a very good chance civil rights are being violated on the regular by law enforcement’s interlopers.
In a 25-page complaint against Rockford Public Schools, filed with the U.S. Department of Education’s Office for Civil Rights, the National Center for Youth Law and the MacArthur Justice Center said that Rockford police officers have been “addressing minor behaviors that should be handled as an educational matter by parents, teachers, and school leaders — and not as a law enforcement matter by police officers.”
The complaint adds: “Black students bear the brunt of this harm.”
These students tend to bear the brunt of the harm everywhere, but it’s made much worse when you add law enforcement to the equation. In Rockford, black students make up about a third of the student body across all Rockford schools. But according to the allegations made in the civil rights complaint [PDF], it’s pretty much only black students being subjected to the worst aspects of RPS’ (Rockford Public Schools) agreement with local law enforcement to provide SROs (school resource officers).
RPS has an agreement with the Rockford Police Department and, as part of its zerotolerance approach to school discipline, routinely refers students to SROs for minor alleged violations of the Code of Conduct. When RPS staff refer students to SROs, SROs in RPS frequently issue municipal tickets.
The impact of RPS’s exclusionary tactics against students of color have repeatedly played out in weekly municipal hearings at Rockford City Hall, where RPS students and their families are subjected to exorbitant fines and forced to miss school. The MacArthur Justice Center and the National Center for Youth Law attended about a dozen municipal ordinance violation hearings to observe the results of student referrals. In the times we attended these hearings, the ticketed students were almost exclusively students of color.
That’s some of the anecdotal evidence. There’s more. The complaint details the hassling of a black female student by an SRO because he claimed he had received a report of smoking in the bathroom. He also claimed the student was the only person in the bathroom at the time of the report, which was clearly false. She and her black friend were the only people subjected to a search. When she questioned the officer about being singled out, she received this response:
“Grow the [f***] up and stop acting like a little brat.”
That’s the level of professionalism we’ve come to expect from police officers when any aspect of their police work is questioned by a civilian. When that questioner is a minor, officers have even less to fear in terms of reprisal, so it can get much worse for those forced to deal with officers alone while on campus.
It’s not just the in-school cops, though. There’s evidence school administrators are aiding and abetting the biased treatment of Rockford students.
[A] Black student from Auburn High School was expelled for over one year (March 4, 2022 to June 4, 2023) over a Category 4 Fighting violation, despite evidence that the student was not at fault: multiple other students reported that the disciplined student had not instigated the altercation, the student who started the altercation admitted to doing so, video footage revealed that the disciplined student had tried to avoid the altercation, and a teacher was on the scene yet chose not to intervene for seven minutes.
That’s insane. And, somehow, it gets worse:
The teacher on scene did not provide a report, and the administrator’s reporting of the incident was inconsistent with multiple statements of witnesses who were present during the altercation. Further, when the initial administrator assigned to the case suggested a less exclusionary punishment for the student—a four-day out-of-school suspension—the administrator was removed from the case and replaced with another. The student was bullied and assaulted first, yet not only did Auburn High School staff fail to intervene, they implemented extraordinarily punitive disciplinary actions against the student.
Again, all anecdotal. But in support of the statistics, which indicate there’s definitely a civil rights problem in Rockford that needs to be looked at by the US Department of Education:
In RPS, a substantial difference has existed for years in the comparison between Black student representation in the student population and Black student representation among those who are referred to SROs for minor school disciplinary matters. In the 2021-2022 school year, Black students represented 31.38% of the student population, yet received 53.1% of referrals to SROs, a 22-point difference. In the 2022-2023 school year, Black students represented 31.03% of the student population and received 54.7% of referrals to SROs, an almost 24-point difference. Similarly, in the 2023-2024 school year (until March 24, 2024), Black students represented 31.62% of the student population, but received 54.7% of referrals to SROs, again a 23-point difference.
And even though the report talks a lot about ticketing, it must be made clear this isn’t low-level stuff, even if the underlying “violations” historically were handled with detention, short suspensions, or just a meeting with parents. Some of these tickets issued to students carry fees as high as $750 per infraction. That’s crippling, especially for low-income students and their families.
This also isn’t a new problem for Rockford. As ProPublica points out, this district was hit with a federal desegregation order after it was discovered the district had been sending black and Latino students to lower-level classes. This didn’t happen decades ago, either. That order was issued in 2001.
Hopefully, the Department of Education will take a long, hard look at this, especially given the Rockford Public Schools’ problematic racial history. And if it does, hopefully it will encourage others to start asking hard questions about police involvement in normal school discipline issues. So far, this law enforcement experiment hasn’t worked out well for students or parents, especially if they’re not white and sitting well above the poverty line.
This lawsuit might be a long shot, but it’s not completely a foregone conclusion at this point. The state of Illinois has tougher privacy laws than most states, which may factor into the judge’s decision. On the other hand, this lawsuit — filed by two Illinois residents with the assistance of the Liberty Justice Center — has been filed in federal court, where assumptions about expectations of privacy won’t necessarily be quite as affected by state law stipulations.
What will help this lawsuit along is just how many automatic license plate readers the state has installed, as well as how many records of people’s movements it has on hand at any given moment. Reason’s Patrick McDonald has the stats on that, and those show this form of surveillance is pretty pervasive, even if it only involves plate/location information.
Illinois State Police received a $12.5 million state grant in 2021 to install cameras, which was more than doubled in June 2022 when Pritzker extended the act, granting up to $20 million in additional funding. As of publishing time, the Illinois Department of Transportation has purchased 652 license plate cameras, of which 340 are installed in Cook County, which includes Chicago.
According to the ISP’s dashboard, in the past month, the system has recorded over 215 million “detections” (when a camera captures a digital image of a license plate) and over 1. 4 million “hits” (when a captured license plate matches a plate on the state police’s “Hot List,” which includes the license plate numbers of stolen vehicles and wanted subjects). Annually, the system records over 1.5 billion detections—more than 100 times the state’s population.
That’s just in Cook County. There are others scattered across the state, but the focal point of ALPR deployment is the Chicago metro area.
It’s the sheer number of readers and total number of “detections” that may sway the court to consider ALPRs more akin to always-on surveillance than just the privacy price to be paid for enjoying the use of public roads.
“Public” is the key word. Areas accessible by anyone at any time (most public roads) aren’t generally treated as areas worthy of a reasonable expectation of privacy. On the other hand, most people aren’t sitting on public roads capturing photos of every car that passes by 24/7.
In total, it seems like a privacy violation. Running a plate against an ALPR database could give the government a pretty complete picture of a person’s movements. But even so, courts have often rationalized that if a single ALPR snapshot isn’t a Fourth Amendment violation, multiplying a non-violation by a several million still doesn’t create a constitutional cause of action.
But now that the Supreme Court’s Carpenter decision is in play, things might change. That ruling said collecting long-term records of people’s movements via cell site location data required a warrant. This is pretty much the same thing, even if the network of ALPRs can’t necessarily produce the same amount of granular location data a person’s cell phone can.
The lawsuit [PDF] figures it’s a question worth asking, no matter what precedent exists. The network of ALPRs — run by contractor Vetted Security Systems and utilizing Vigilant’s software to maintain the collection of plate/location records — allows cops to track pretty much anyone traveling in or through Cook County, allowing them to determine where people worship, shop, seek medical help, or what political groups they associate with. So, there’s a First Amendment concern closely aligned with the more immediate Fourth Amendment-related cause for concern.
The lawsuit maintains that collecting plate data is a search under the Fourth Amendment and that the millions of “searches” performed by the plate readers cannot possibly be supported by probable cause or even reasonable suspicion.
It is an unreasonable search when the government tracks the movements of every citizen who drives a car just in case it might someday have reasonable suspicion as to one of the millions of people being tracked.
Defendants do not have any substantial or exigent government interest that would justify searching every citizen who drives a car, every day, and retaining that record of every citizen’s movements.
The plaintiffs seek an injunction blocking the State Police from utilizing its current ALPR system and preventing it from adding additional cameras to the network it already has in place.
It’s an interesting set of arguments. But it will be a tough case to win given the lower expectation of privacy given to drivers on public roads. Pretextual stops exist because of this lower constitutional standard and probable cause isn’t needed to engage in fishing expeditions. ALPRs have their problems but so far, no court has declared them unconstitutional to deploy without a warrant.
While there’s a slim chance a warrant requirement might someday surface in some court, it’s likely it will only affect searches of stored plate records, rather than deployment and use of the devices themselves. Unless this court is willing to buck the trend, the Illinois State Police is unlikely to lose access to its massive network of plate readers.
Whatever your thoughts on policing in general in America, I would hope it would be largely uncontroversial to state that a huge percentage of Americans believe that police are generally over-militarized and at least slightly a little too trigger happy, especially when it comes to engaging minority communities. If you somehow think that there isn’t at least a perception problem among the public here, then you probably don’t need to keep reading the rest of this post, because it’s not going to make sense to you.
But if you do understand that there is some level of a problem here, your skin will almost certainly crawl when you see the recruiting poster the Peoria, IL police put out on social media to try to get young recruits.
A Peoria, Illinois police department tried to recruit new officers with a Call of Duty-inspired campaign on social media, and it was as tone-deaf as you’d imagine. The post, originally shared on the Peoria Police Department’s social media page, showed three white men posing with guns while wearing tactical gear. “Stop playing games and answer the Call of Duty,” the post reads, with the “Call of Duty” portion of the poster written in the same text as Activision’s wildly popular (and more than occasionally problematic) first-person shooter franchise.
Imagine just how tone-deaf you have to be in the current climate of policing in America to put this poster out. First, recruiting people with images of police in tactical gear pointing guns is precisely the wrong message you want to put out to a community in Peoria that is concerned about policing. Doubly so when the image is of three white cops in a community with a sizable black population.
And now add to all of that the simple fact that Call of Duty is a game in which you primarly spend a great deal of time shooting individuals. Like, with bullets and stuff. You know, to kill them. And, sure, it’s a video game and in that context I don’t have an issue with the game itself. But in a society where many believe that police far too often see themselves as gun-toting enforcers through violence, recruiting against a video game like CoD is absurd.
Police Chief Eric Echevarria eventually took the post down and apologized in a way that I will say does ring through as genuine.
It was never my intention to offend any of our community members with the recruitment flyer that was posted on our Facebook page yesterday. It was simply a recruitment image I thought would appeal and connect to a younger generation. I take ownership of this, and I sincerely apologize. Our goal is to recruit the best and most qualified officers for this police department in the most caring and respectful way.
It’s probably a good move, because we haven’t even gotten into the issue of intellectual property. The poster does name the game and use the same or similar font for the game’s branding when doing so. While I’m not sure there’s an actual trademark infringement case to be made here, I am also quite sure that Activision probably wouldn’t appreciate the use of its product name and branding in this way.
And so the poster is down, but the damage is done. In a community where fear of police violence is very real, that community got a reminder of how some police officers see their jobs.
Dating can be difficult, but there are certain things you can do to not make things worse on yourself. Don’t be a creep. Be kind. Take no for an answer. Actually listen to the people you date. I mean, that’s kinda the standard stuff.
Nikko D’Ambrosio was apparently unable to follow at least one (and possibly more!) of those simple rules. Nikko, a 32-year-old Chicago man (old enough to know better), apparently dated around a bit, then lost his shit when he discovered that some of the women he dated went to the Facebook group “Are We Dating the Same Guy” to offer what were mostly pretty mild complaints about him.
“Very clingy very fast,” the woman commented. “Flaunted money very awkwardly and kept talking about how I don’t want to see his bad side.”
More screenshots showed the woman — who commented as an anonymous member — claimed that after she blocked D’Ambrosio’s number, he used a different number to send her a text in which it appears he attacked her appearance.
Nikko didn’t too much like this. And the guy once described as “very clingy very fast” who allegedly told someone you “don’t want to see his bad side” showed off his bad side in filing this very obvious SLAPP suit against basically anyone he could think of. There are 56 total defendants, including 29 women (some of whom are just relatives of the people he’s actually mad at). There are also 22 variations on Meta/Facebook. While the company has multiple corporate entities, you do not need to sue them all. For good measure, he also sued Patreon and GoFundMe, because why not?
It’s not at all clear why he sued all of those defendants. Most of the individual defendants are not clearly connected to this case. The case only names one woman who he says made defamatory comments about him (they’re not, but we’ll get to that). The rest are just… thrown in there and never explained. Did they like or share the original comments? Who knows. It does appear he sued family members of the main woman he’s mad at, again, for what?
There are so, so, so many problems with the lawsuit I’ve literally restarted this paragraph about six times as I change my mind on which to cover first. But let’s start here: Section 230. As far as I can tell, D’Ambrosio’s lawyers have never heard of it. The complaint doesn’t address it. But it easily bars the lawsuit against all of the many Facebook defendants, as well as Patreon and GoFundMe. He also sues AWDTSG Inc., which is apparently a company that helps to run a series of local “Are We Dating the Same Guy” groups on Facebook, which is what Nikko is particularly pissed at.
Section 230 says that for things like defamation, you get to sue the party who said the actual defamatory thing, not the website that hosts the speech. Should the case even get that far (and it’s not clear that it will), all the Facebook/Meta parties, GoFundme, Patreon, and AWDTSG will easily get their cases tossed on 230 grounds. Having a lawyer file a lawsuit like this without understanding (or even attempting to address) Section 230 seems like malpractice.
Indeed, the lawyers who filed this lawsuit, Marc Trent and Dan Nikolic, kind of parade their ignorance. In the lawsuit they claim that because of “Defendants content moderation responsibilities” they would have had to “review” the posts, and that makes them liable for the alleged defamation. But, um, Section 230 was passed directly to deal with exactly that scenario, and to say that, no, reviewing posts doesn’t make you liable.
And Section 230 protects not just “interactive computer services” but “users” who pass along third party content. So even if he’s suing people for sharing or liking the comments he’s mad about, all of those defendants are protected by Section 230 as well.
It’s stunning that the lawyers in question seem wholly unaware of this.
Next up, defamation. Nothing in the suit appears even remotely close to defamation. The statements all appear to be statements of opinion about what kind of creepy jerk Nikko is. Sorry, Nikko, people are allowed to have opinions of you. That’s not defamation. Nearly all of the statements are clearly opinion statements. And, no, it may not feel great, but opinions that you’re “very clingy, very fast” are not defamatory.
Also, in a defamation suit, you plead which statements were defamatory, including why they are false and defamatory. This complaint does not do that.
Next, they’re trying to use Illinois’ brand new (just went into effect this year!) “doxxing” law, claiming that talking about him and posting his picture violates the law. Now, I think there are some potential 1st Amendment issues with that law, and they’re really driven home by using it here. But to try to make sure that this law is on the correct side of the 1st Amendment, it says that the law is not violated when the speech in question is “activity protected under the United States Constitution,” and boy, lemme tell ya, calling a dude “very clingy” sure qualifies.
There are a bunch of other pretty big legal problems with the lawsuit that are just embarrassing. Ken “Popehat” White covered many of them in his post on this subject. The big one, suggesting that the lawyers have little (if any) familiarity with federal court, is that to file in federal court over state law claims, you have to show “diversity,” meaning that the parties in the case are all in different states. And White notes how badly they fucked that up:
D’Ambrosio’s lawyers assert diversity jurisdiction but make an utter dumpster fire out of it. They admit that both D’Ambrosio and at least one of the defendants come from Illinois, which defeats diversity jurisdiction. They admit they don’t know what state a bunch of the defendants come from. They identify a bunch of the defendants as limited liability companies, but don’t plead the facts necessary to identify those entities’ citizenship for purposes of diversity. This is the kind of thing that makes federal judges issue orders of their own accord saying, in judicial terms, “what the fuck is this shit?”
Also, the lawyers claim it’s a “class action” lawsuit, and are actively seeking to recruit more plaintiffs on Reddit, naturally (where — hilariously — the person who originally posted the topic asked the lawyers if they wanted him to start a GoFundMe, apparently not realizing GoFundMe was one of the defendants in the case). Class action defamation lawsuits aren’t really a thing, because for it to be defamation it has to be a statement about a specific person, and the specifics matter. But even beyond that, if you’re filing a class action lawsuit, you have to take some steps, and as White points out, these lawyers didn’t do that:
The caption of the lawsuit proclaims that it’s a class action, and D’Ambrosio’s lawyers have made comments suggesting that they see themselves as suing on behalf of “victims” other than D’Ambrosio. But other than the caption, the lawsuit contains not a single relevant allegation about being a class action. It doesn’t plead any of the factors necessary to qualify as a class action. It’s also obviously unsuited to be a class action: a class action requires a pool of plaintiffs with factually and legally similar claims, but defamation claims are by their nature very individual and context-specific, and each aggrieved man’s case would be very different depending on what was said about them.
White notes that the lawsuit is so badly drafted that he expects it may get dismissed just on the jurisdictional problems without defendants even having to file anything. He also suggests it’s so bad that it could lead to sanctions from the judge.
But, also, this is exactly the kind of case for which I coined the term Streisand Effect nearly twenty years ago. Doing this kind of shit won’t protect your reputation, it will destroy your reputation. And, again as White points out, a good lawyer would warn you of that before filing this sort of lawsuit. Whether or not they warned him about it, the lawsuit has been filed and now the allegedly “very clingy, very fast” guy who might be “very awkward” is, well, having his reputation spread pretty far and wide.
And there are many, many more. So rather than just the types of people who hang out on the “Are We Dating the Same Guy” Facebook groups, now many, many, many more people — some of whom I’d assume are in the dating pool in the Chicago area — are aware of Nikko D’Ambrosio and his reputation. And not just his reputation for being very clingy, very fast, but his reputation for filing bullshit SLAPP suits to try to silence women for expressing their opinion of him.
Hopefully the judge does dump the case. While Illinois does have a decent anti-SLAPP law (which would clearly apply here), the 7th Circuit has suggested it does not apply in federal court (of course, because of the jurisdiction issues, this case doesn’t apply there either, but… whatever).
More importantly, this is a case that demonstrates yet again why Section 230 is so important to protect people against harassment like this very lawsuit. Without Section 230, it becomes way easier to abuse the legal system to try to silence women who point out that you’re a creep. Section 230 protects that kind of information sharing.
The whole case is a mess of epic proportions. It’s a lawsuit that never should have been filed, but now that it has, congrats to Nikko D’Ambrosio for making sure every dating-eligible woman in Chicago knows to avoid you.
Across the nation, bigoted politicians (of the Republican variety, almost exclusively) are trying to punish and silence content and expression they don’t like.
It’s not like it’s even a close question about who’s doing this and why. A slew of bills targeting drag shows and LGBTQ+ writing have been tossed into legislatures all over the nation. Some of those have become law. Most of those that have become law have been challenged in court — challenges often followed swiftly by injunctions prohibiting their enforcement.
But that hasn’t stopped a very motivated, very ignorant subset of politicians from continuing to push laws that threaten civil liberties. And — win or lose — it hasn’t stopped a very determined, extremely minute subset of individuals from trying to make the United States a worse place to live for anyone who isn’t straight and white.
According to an analysis by the Post, 60% of book challenges made in the 2021-2022 school year came from the same 11 adults. […] The majority of objections were on books authored by or about LGBTQ+ people or people of color.
None of these people are worried whether or not children might have access to books like, say, Mein Kampf or The Protocols of the Elders of Zion or even the super-sexed up compositions of a dozens of romance novelists. Nope, the publications these 11 people (and the politicians who cater to them) are concerned with deal with certain topics these people would rather children had no knowledge of.
Nearly half of the challenges in The Post’s database, 43 percent, targeted titles with LGBTQ characters or themes.
[…]
Thirty-six percent of targeted books featured characters of color or dealt with issues of race and racism. Of the top 10 most challenged books in The Post’s database, five fell into this category: George M. Johnson’s “All Boys Aren’t Blue,” Toni Morrison’s “The Bluest Eye,” Jonathan Evison’s “Lawn Boy,” Ashley Hope Pérez’s “Out of Darkness” and Angie Thomas’s “The Hate U Give.”
The good news is that none of this shit is going to fly in Illinois. A bill [PDF] signed by Governor JB Pritzer last year took effect January 1st. It’s a ban on book bans, and it means the tactics deployed by the 11 people noted above (along with groups like Moms for Liberty) won’t be nearly as effective in Illinois as they have been elsewhere.
The new law contains a statement of intent from state legislators:
It is further declared to be the policy of the State to encourage and protect the freedom of libraries and library systems to acquire materials without external limitation and to be protected against attempts to ban, remove, or otherwise restrict access to books or other materials.
It sounds pretty good until you look at the text of the law, which leaves it up to publicly-funded libraries to fight back against censorship with no guarantee the state of Illinois will always have its back. The law ties state funding to ban resistance at the library level — something that can easily be overridden by future laws that might, say, tie funding to complying with state or local-level book bans.
In order to be eligible for State grants, a library or library system shall adopt the American Library Association’s Library Bill of Rights that indicates materials should not be proscribed or removed because of partisan or doctrinal disapproval or, in the alternative, develop a written statement prohibiting the practice of banning books or other materials within the library or library system.
Cool, I guess. If the legislative intent is just “Hey, don’t ban books or we’ll take your money,” mission accomplished. Sure, this might make it easier for libraries to reject book challenges by pointing challengers to the law that ties funding to open access to content. On the other hand, adopting a private party’s “bill of rights” isn’t going to protect the state’s libraries from being forced to cooperate with book bans handed down by state or local politicians.
To actually protect libraries against current and future enemies, the state needs to codify this prohibition of book bans at the state level. And it should do this. There’s no reason it shouldn’t. Protecting libraries from future book bans isn’t going to turn libraries into vast repositories of pornography. All it’s going to do is protect libraries (and their users) from content bans the next time the prevailing political winds shift.
Sure, this makes it slightly more difficult for state pols to enact book bans that target public libraries by tying their funding to these stipulations. But those most likely to push statewide book bans don’t really care whether or not people have free access to published works. All that matters to them is that certain works dealing with certain subject matter written by certain people won’t be available to anyone who doesn’t have cash on hand to purchase these works.
Nice try, Illinois. But try harder. This is barely better than nothing at all.
The thin blue line between cops and cop-friendly tech continues to be erased, mostly by cops. No longer content to underserve the public, law enforcement agencies are welcoming the warm embrace of consumer surveillance products in hopes of adding private tech to their publicly-funded surveillance mesh networks.
Ring, Amazon’s home surveillance tech acquisition, was one of the first to successfully merge market expansion with law enforcement self-interest, resulting in Ring handling the PR work while cops handed out “free” cameras to locals with the implicit suggestion recipients of freebies might not ask for a warrant before handing over their security cam footage.
This unnatural relationship has only become more explicit over the last few years. Ring continues to swallow the market, helped in no small part by its conversion of police departments into marketing teams. Flock, a Ring competitor that also offers automated license plate readers, has managed to convert gated communities and government agencies into unpaid PR reps. Helping out with this effort are lazy “journalists” more than willing to publish police press releases verbatim and only seek comment from Flock reps and cop spokespeople who see nothing wrong with co-opting private cameras for public use.
That’s how local papers end up running “reporting” that features the Flock brand name a half-dozen times in the space of 400 words. And that’s how these private companies are able to quote local “reporting” while pitching products to private buyers, as well as the law enforcement agencies hoping to make these cameras a part of their own surveillance networks.
But rarely does it get more explicit than this. The city of Wheaton, Illinois has managed to cross the line from mutually advantageous to incestuous by turning its own website into a storefront for a consumer-facing surveillance camera company.
As the City continually seeks to promote and enhance public safety in our community, the Wheaton Police Department is enlisting the public’s help with a new safety initiative, Connect Wheaton. This program consists of an online security camera registry at www.connectwheaton.org where residents and businesses can register the location of their security cameras with the Wheaton Police Department to help expedite emergency response and crime investigations.
Being able to determine where there are security cameras – including video doorbells, home security systems and commercial surveillance cameras – significantly enhances the Wheaton Police Department’s response efforts. With this information, Wheaton Police Department detectives can quickly determine if video evidence might be available at a particular location and whom to contact to request it.
Absolutely. Knowing where cameras are would help law enforcement solve crimes. That’s indisputable. And a registry, as proposed by the City of Wheaton, would pinpoint location as well as provide contact info so cops can ask for footage via personal request or demand it with a warrant. Nothing about this — SO FAR! — is particularly unusual.
It starts getting weird quick, though
Residents and businesses can register their cameras with the Wheaton Police Department through the self-service portal at connectwheaton.org. Your information will be kept confidential and only accessed in the event of a criminal investigation or emergency incident.
First, this assurance is meaningless. When cops say your information “will be kept confidential,” they mean from everyone but themselves. Limiting access to investigations or “emergency incidents” is just as meaningless, considering the police can initiate “investigations” for little or no reason. And “emergency incident” is there to cover any situation where cops access people’s information when nothing is currently under investigation.
The city’s statement does note that registration does not give officers’ live access to registered cameras. While that seems like a government entity demonstrating its interest in protecting the constitutional rights of residents, this is really nothing more than the city stating a logistical reality: info on camera location, as well as the owner’s personal data, is not capable of providing direct or on-demand access to live footage or recordings.
But things really start to look ugly when you visit the city’s website, which not only allows residents to register cameras, but pushes them towards purchasing products from the city’s preferred provider, Fusus.
To share your cameras, all you need is a small fususCORE device that plugs into your camera system. Once it’s set up, it enables camera sharing based on your settings without impacting your network.
Are you, the proverbial Wheaton resident, unsure of where to get this “fususCORE” and/or incapable of performing a perfunctory Google search? Great news! The City of Wheaton allows you to purchase approved surveillance devices compatible with the city’s surveillance network and desires directly from its publicly-funded website.
There’s a memorandum of understanding (MOU) between the Wheaton PD and Fusus that the site calls “Terms and Conditions.” But unlike most ToCs, it has nothing to do with purchasers’ agreements with Fusus and everything to do with what the PD gets from this lucrative (in more than just financial terms) agreement with its chosen provider.
You know, things like this, which says the department can go through Fusus directly to obtain footage from private cameras, despite suggesting otherwise in the statement on the city’s website.
Partner grants video access to Department for videos designated by Partner that are owned by or under management by Partner.
Are cameras or tech sold through the city’s website considered to be “owned or under management?” Are registered devices considered to be “under management?” The MOU doesn’t say. And neither does the city, which has only offered the assurance there will be no real-time access to privately-owned cameras… unless the camera owner agrees to do so via a handy “panic button” included in the Fusus camera management app.
The MOU also says the PD can view recorded footage (after gaining access through Fusus) even when there’s no emergency or criminal investigation underway.
Video access by Department does not constitute commitment on the part of Department that video will be viewed in emergencies or when requested by Partner.
This is some bullshit. City residents are encouraged to purchase compatible surveillance tech via the city’s website. The included “Terms and Conditions” have nothing to do with private residents or their purchases. The agreement being made when residents buy cameras through the city’s site isn’t between them and Fusus. It’s an agreement between Fusus and the PD — one that says the PD is under no obligation to abide by the constraints stated in the city’s announcement: restraints that would restrict access to criminal investigations or emergency situations. The MOU says the PD can get the footage directly from third parties and it doesn’t even need to demonstrate it’s doing this for any particular law enforcement purpose.
Fortunately, Wheaton residents have the most powerful option in their hands: inaction. They’re not required to register cameras or buy Fusus add-ons to make it easier for cops to obtain recordings without their express permission. All they have to do is nothing to thwart this expansion of the government’s surveillance powers. And, as we all have observed from decades of low voter turnout, doing nothing is something most citizens do best.
Some city officials in Illinois are now engaged in a round of “How Can I Get Sued?” Sounds like fun, but Calumet City officials might do well to remember the only way to win is not to play.
That’s the upshot of the latest bit of officious nonsense to surface in the Chicago area. Granted, it’s far more innocuous than unjustified killings perpetrated by cops or law enforcement operating its own off-the-books, rights-free interrogation black site.
But it’s far from harmless. This suburb of Chicago — as poorly represented by elected representatives and the law enforcement agency they oversee — has decided it’s time to start punishing journalists for doing journalism, as Gregory Platt details in this report for the Chicago Tribune.
Calumet City officials have issued municipal citations to a Daily Southtown reporter who they allege violated local ordinances by seeking comment from public employees on major flooding issues in the area.
Several notices sent to reporter Hank Sanders describe the alleged violations as “interference/hampering of city employees.”
Now, there’s something you rarely see on a Civics test. How does one “hamper” a city employee, if one were so inclined (or not even inclined, as is the case here) to do so?
There’s no clear answer here. This is how it went down in Calumet, though. “Hampering” — like all the best laws — is interpreted subjectively.
Hank Sanders apparently had several questions about the city’s storm water facilities, which were apparently already in poor condition prior to their inability to handle September’s historic rainfall. After widespread flooding in the city’s poorest neighborhood, Sanders hounded city officials, including Mayor Thaddeus Jones, with questions about these facilities.
At some point, these officials decided Sanders had asked too many questions. Rather than respect someone who firmly believed the best modifier for “reporting” is “dogged,” these officials decided to hit Sanders with citations for… well, what exactly?
“Despite all FOIA requests being filled, Hank Sanders continues to contact city departments and city employees via phone and email,” the violation notice mentioning Jones states. “Despite request from Calumet City attorneys to stop calling city departments and employees, Hank Sanders continues to do so.”
Rather than simply “no comment” their way out of these interactions, the city decided to fine Sanders for asking questions. And while a “no comment” is never satisfactory, it at least does not come with fines and fees attached.
Continuing to ask questions after being given some answers is what these officials apparently believe satisfies the legal definition of “hampering.” And that belief is just as ridiculous as this response to Sanders and his ongoing queries.
I’m sure these particularly officious officials will be startled to learn that these fines and fees won’t stick because there’s simply no way for Sanders to determine when he’s crossed the line from performing his journalistic duties and (in the legal sense) “hampering” city employees.
“Between the dates of October 4th and October 12th Hank Sanders sent fourteen (14) emails to the city of Calumet City reference the recent flooding,” the Wilson notice states.
What is he supposed to glean from a legal notice like this one? Is 14 emails one too many? Would 12 be acceptable? Is it that 14 emails were sent in nine days? If 14 emails were sent over a ten-day period, would that be non-hampering? In other words, there’s nothing in this that makes it clear where persistence becomes legally actionable harassment under the ordinance being used to punish Sanders for continuing to demand answers from elected officials.
And, as long as Sanders can’t define it and city leaders can’t explicitly say what does or does not constitute a “hampering,” it remains exactly what it appears to be: a ham-fisted effort to silence a journalist who’s done nothing more than engage in acts of journalism. First Amendment litigators, start your engines!
Well, this is an unfortunate turn of events. The last time we discussed this issue in this state (March 2019), a state appeals court came to the opposite conclusion: compelling password production is a violation of rights.
That ruling said the foregone conclusion doctrine didn’t apply, at least not the way the state wanted it to apply. The state said the only thing it needed to show was that the phone likely belonged to the criminal suspect. If it could provide enough evidence linking the phone to the arrested person, and could make the reasonable assumption the device contained evidence, these conclusions would allow compelled password production to bypass the Fifth Amendment.
That’s not what’s actually at stake here, the appeals court replied. The government wasn’t interested in the passcode. It was actually interested in what the device contained, which it could access more easily if the defendant was forced to unlock it.
While the State is aware that the passcode existed and that Spicer knew it, the State could not know that the passcode was authentic until after it was used to decrypt Spicer’s phone. Moreover, the production of Spicer’s passcode would provide the State more information than what it already knew. Although the focus of the foregone conclusion is on the passcode, in our view, it properly should be placed on the information the State is ultimately seeking, which is not the passcode but everything on Spicer’s phone.
That was the call made by this appeals court in the Spicer case — a ruling that did not go so far as to call all compelled production a Fifth Amendment violation, but one that made it clear the “foregone conclusion” analysis should be applied to what the state is actually seeking, rather than what it assumes about phone ownership.
This decision (People v. Spicer) was applied by the district court in another criminal case. The court reached the same conclusion the appeals court did: compelled password production is a Fifth Amendment violation.
The state’s Supreme Court, however, has recently reversed that decision. (h/t FourthAmendment.com) And in doing so, it has not only nullified the findings in Spicer, but established precedent that says the only foregone conclusion the government needs is the one connecting the phone to the criminal suspect.
And it reaches its conclusion despite acknowledging the password is not really what the cops want. They want an unlocked phone so they can access everything inside of it. This is from the decision’s [PDF] discussion of the practical effects of the lower court’s ruling.
The search warrant issued allowing a search of defendant’s phone, and the circuit court entered an order denying the State’s motion to compel defendant to provide the passcode to the phone. In determining whether the circuit court’s order effectively quashed the search warrant, we observe that the definition of “quash” is “[t]o annul or make void; to terminate.” Black’s Law Dictionary (11th ed. 2019). Here, the search warrant authorized officers to search defendant’s phone and required defendant to unlock the phone so officers could execute the warrant. The circuit court’s denial of the motion to compel eliminated the requirement for defendant to comply with the search warrant. As such, we conclude that the circuit court’s order annulled or voided the search warrant; thus, it had the substantive effect of quashing the search warrant.
We further conclude that the circuit court’s denial of the motion to compel effectively suppressed evidence. Although the denial did not directly suppress specifically identified evidence, it prevented the State from accessing any evidence on the phone and presenting it to the factfinder, thereby having the substantive effect of suppressing evidence.
The government didn’t want the passcode. It wanted an unlocked phone. The search to be performed did not target a passcode, but everything the passcode would provide access to. Police didn’t have much evidence connecting the seized phone to the alleged crime (forged checks being deposited via mobile deposit), but still insisted the defendant should be forced to unlock the phone. There wasn’t much in the way of any “foregone conclusions,” no matter which standard the lower court applied.
[Detective Todd] Ummel believed defendant’s phone contained a photograph of the checks, and he was “hoping to find” such a photograph. Ummel further sought additional files pertaining to the mobile deposits. He conceded, however, that he did not know for certain that any such files existed and that there was currently nothing connecting defendant to the transactions besides Spurling’s statements. Ummel added that he had not attempted to subpoena records from defendant’s cell phone carrier to obtain copies of text messages.
[…]
Applying those principles, the circuit court observed that Spurling’s statements were the only evidence linking defendant’s phone to the transactions in question and it would be speculative to presume that a photograph of the checks would remain on the phone after the transactions were complete. Though the circuit court did not perceive the State’s endeavor as a fishing expedition, it concluded that the State did not establish with reasonable particularity that, at the time it sought the act of production, it knew the evidence existed, the evidence was in defendant’s possession, and the evidence was authentic.
The appellate court (not the same one that handled the Spicer case) reversed the lower court’s decision, declaring compelled passcode production to be harmless in terms of the Fifth Amendment.
In this case, the appellate court declined to follow Spicer and concluded that the compelled production of the passcode is nontestimonial, reasoning that a passcode may be used so often that retrieving it “is a function of muscle memory rather than an exercise of conscious thought.” 2021 IL App (4th) 210180, ¶ 59. The appellate court asserted that “a cell phone passcode is more akin to a key to a strongbox than a combination to a safe.”
Having decided that this act was nontestimonial, it didn’t even bother to apply the foregone conclusion doctrine and skipped straight to siding with the government’s assertions. That led to this appeal, which asked the state Supreme Court to decide whether or not compelling password production violates Fifth Amendment protections against self-incrimination.
The state of Illinois had plenty of friends pitch in on its behalf:
Before proceeding with our analysis, we acknowledge that this court granted a motion of Indiana, Arkansas, Florida, Idaho, Louisiana, Minnesota, Mississippi, New Jersey, North Dakota, Oklahoma, Oregon, South Carolina, South Dakota, Utah, and Virginia (collectively, amici states) to file an amicus curiae brief in support of the State’s position on appeal.
So, there’s a handy list of states where governments feel citizens have too many constitutional protections… at least when it comes to phone searches. Good to know.
The state’s top court says producing a passcode is testimonial, but not testimonial enough. The Fifth Amendment does not apply.
To summarize, the State established that, at the time it sought the act of production, it knew with reasonable particularity that the passcode existed, the passcode was in defendant’s possession or control, and the passcode was self-authenticating. These implicit facts add “little or nothing to the sum total of the [State’s] information.” Fisher, 425 U.S. at 411. In other words, the act of entering the passcode has no testimonial value, as the facts implicit in the act are already known by the State. Therefore, the facts are foregone conclusions and insufficientlytestimonial to be privileged under the fifth amendment. For these reasons, we conclude that the foregone conclusion doctrine applies as an exception to the fifth amendment privilege in this case.
That’s the call. The dissent, however, says the majority is forgetting there’s another constitution in the mix here.
Because police have all the cell phone’s contents, they may use any means at their disposal to decrypt the contents but one: they must not compel Sneed to decrypt or translate the contents of the cell phone. The Illinois Constitution provides: “No person shall be compelled in a criminal case to give evidence against himself ***.” Ill. Const. 1970, art. I, § 10. Prosecutors intend to use the decrypted contents to prove Sneed committed forgery. The appellate court’s order compels Sneed “in a criminal case to give evidence against himself,” and therefore it violates article I, section 10, of the Illinois Constitution.
The dissent goes on to point out investigators had other options. They just decided not to use them because it wasn’t worth the expense.
The Illinois State Police, De Witt County, and the Clinton Police Department understandably decided that the prosecution of Sneed for forging less than $1000 worth of checks did not justify the expense of hacking or commercial decryption. The circuit court’s order denying the State’s motion to compel Sneed to decrypt the cell phone’s contents left the police and prosecutors with a choice of either spending thousands in pursuit of decryption to lead to a conviction for a relatively minor offense or trying to obtain the conviction without the decryption.
But somehow the government is fine spending thousands on a single lowball prosecution in hopes that it might be easier in the future to bypass constitutional protections to engage in other lowball prosecutions.
And it worked. The state spent an untold amount of taxpayers’ money seeking precedent that diminished their constitutional protections. Now, it’s free to compel decryption in almost any criminal case, even if it has plenty of other means of obtaining evidence. The state wins. Illinoisans lose.
Protecting against threats means determining what your threat level is. Demanding everyone utilize a 53-character password with uppercase letters, numbers, and “special symbols” generally just makes people more irritated, rather than more secure.
Obviously, things must be secured. And passwords shouldn’t be so simple that anyone with an off-the-shelf HP desktop can hack them.
But people in charge of security need to weigh perceived threats against security responses. What they absolutely shouldn’t do is hammer the RESET button without considering the consequences of their actions.
When we first enter school, we’re constantly told to “be on our best behavior.” Apparently, that same warning doesn’t apply to educators. An Illinois school did one of the right things: it asked for an audit of its security. Its response, however, indicated no one at the school security level was on their best behavior. Here’s Lorenzo Franceschi-Biccierai with the details for TechCrunch:
Last week, Oak Park and River Forest (OPRF) High School in Illinois told parents that during a cybersecurity audit, “due to an unexpected vendor error, the system reset every student’s password, preventing students from being able to log in to their Google account.”
“To fix this, we have reset your child’s password to Ch@ngeme! so that they can once again access their Google account. This password change will take place beginning at 4 p.m. today,” the school, which has around 3,000 students, wrote in an email dated June 22. “We strongly suggest that your child update this password to their own unique password as soon as possible.”
Yikes. I realize a blanket reset is far easier than simply revoking passwords to force end users to create a new one, but this is all sorts of wrong. Even if the school didn’t have a Plan B for this occurrence, it could not have done worse than informing everyone that everyone has the same password until each individual made the effort to change it.
And this was handled during the school off-season, which means the email was likely ignored or back-burnered by many recipients. But those who did read it — and any malcontents who might have realized what this reset meant — now had all the information they needed to access any account run by this school.
Fortunately, this doesn’t appear to have attracted the attention of malicious individuals. And the school has performed another reset that is far less stupid. The new reset involves sending every user their own “special password” via email, which should limit the collateral damage.
But before the damage was mitigated, not only could people access other people’s stuff, but they also had no functioning option to prevent others from accessing their stuff.
Manning Peterson, the mother of an OPRF student, replied that “this is terribly insecure and you have just invited every single students [sic] accounts to get hacked.”
Peterson said that after this email, she tried to reset her son’s password but it wasn’t possible.
“My son and I were able to log into several of his peers [sic] google accounts, which gave access to all emails, papers, class work—anything saved on google drive (docs sheets and slides),” Peterson said in an email to TechCrunch.
Manning Peterson isn’t being paid to ensure the school’s systems are secure. But that’s the service she ended up performing. Offloading the security responsibility on end users isn’t a great way to handle perceived security flaws. Giving every end user the power to see every other user’s information is a horrendous way to respond to a security audit.
Things may be (at least temporarily) under control at Oak Park and River Forest. But this catastrophe isn’t going to ensure any student, staff member, or parent that further fuck ups aren’t inevitable.