Caveat 4.9.26
Ep 303 | 4.9.26

Privatizing cyberspace.

Transcript

Dave Bittner: Hello, everyone, and welcome to "Caveat", N2K CyberWire's privacy surveillance law and policy podcast. I'm Dave Bittner, and joining me is my co-host, Ben Yelin, from the University of Maryland Center for Cyber Health and Hazard Strategies. Hello there, Ben.

Ben Yelin: Hello, Dave.

Dave Bittner: On today's show, Ben has a story on local governments choosing to shut down Flock license plate readers due to privacy concerns. I've got an analysis of proposed offensive cyber operations for the private sector. While this show covers legal topics and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. [ Music ] All right, Ben, it's good to be back. I feel like we got the band back together here. Yeah, it's been a while. Well, big, big thanks to Ethan Cook, who filled in admirably. Absolutely.

Ben Yelin: While we were at our various absences.

Dave Bittner: Yeah.

Ben Yelin: But it's definitely good to be back in the saddle with you. Nice to have a bench that we can rely on, and Ethan is that bench. Absolutely. It means for our listeners fewer encore episodes. As much as we enjoy those, we can bring you new content because of how well Ethan fills in for us.

Dave Bittner: There you go. All right, well, why don't we dig into our stories here? You want to kick things off for us, Ben?

Ben Yelin: Sure. So my story comes from The Guardian newspaper, and it talks about growing resistance across U.S. localities to the use of Flock safety cameras.

Dave Bittner: Yeah.

Ben Yelin: We've talked about this in the past, but it's an AI-powered surveillance system that reads license plates and tracks vehicle movements. So the surveillance is of license plates, which is a very effective surveillance tool to figure out where people are going and where they have traveled in a way that's somewhat similar to historical cell site location information. You can create a pretty good dossier of a person's life and the whole of their movements by tracking their license plate. And this has been marketed to local governments as a crime-fighting tool. A lot of local governments in all different types of jurisdictions, big cities, small towns, blue areas, red areas, have embraced having Flock safety cameras just as a way to conduct criminal investigations. But there's been a big pushback from civil liberties groups. And now for the first time, we're actually seeing some cities back out of agreements they previously had with Flock. And that has kind of broader policy implications. And this is an issue that I think states are going to have to step up and address because there really is a balance to be struck here between the capability that these cameras provide, but the need to protect people's privacy. And when we get into the use cases, like there are both very, very beneficial use cases, but also very problematic use cases. So basically, we have these license plate readers, streets, utility poles. It reads license plate numbers, make, model of the vehicle, and then obviously metadata, so it's time and location stamped, stored all across the centralized database. And so there are AI implications for that. Law enforcement agencies can analyze a large amount of data using AI tools. And not only that, they can share with other law enforcement agencies, which from a fighting crime perspective is excellent because crime certainly travels across borders. And it's good to share knowledge among departments. But from a civil liberties perspective, when data from your small town could be sent to law enforcement agencies across the country, that could certainly put you at risk for invasions of privacy. But opposition has started to grow. You've seen pushback at city council meetings, and it really revolves around a bunch of things. For one, a lot of the contracts that Flock agreed to came with very little oversight, and there really wasn't consent from the public or any kind of transparency as to the full powers of Flock. Flock recently removed contractual language stating that it does not own or sell collected data, which was alarming to people who follow this issue closely. Flock is kind of hurt by its own tendency to mouth off on its website. Like, they'll be like, here's what we're doing. I'm going to write a blog post about -- and so they said that, like, this change was non-substantive. We're just kind of language policing our policies, our contractual language.

Dave Bittner: Yeah.

Ben Yelin: But obviously that raised a lot of concerns. And then security. So, you know, privacy and security, big theme, always kind of have a very interesting interplay with one another. And some hackers have shown that they can access live camera feeds. Basically, there's some type of vulnerability here. Not to get too much into the details, but, like, if you press the button on the front of one of these things three times, some type of trigger is -- I don't know.

Dave Bittner: It goes into some kind of mode.

Ben Yelin: Exactly. Which reveals, like, a lot of very sensitive information and could give people real-time access to these security -- or real-time access to these cameras. And that goes against what Flock has been saying since they started as a company, that they have kind of robust cybersecurity safeguards.

Dave Bittner: Yeah.

Ben Yelin: And then the other thing is just the broader policy implications of this. It's great for prosecuting local crime, but when you start to realize kind of the function creep here, that it could be used not just for solving local crime, but for things like immigration enforcement. In states where abortion is illegal, it can be used to track people who are going out of state. So those types of civil liberties concerns are very, very pleasant -- are very, very present.

Dave Bittner: Unpleasant, Ben. They're unpleasant.

Ben Yelin: They are unpleasant and quite present. So a bunch of jurisdictions have suspended or terminated their contracts. I think a big impetus for this is just seeing how little control local governments have in how long data is stored. It's stored indefinitely, and also who can access it. The fact that once the data is collected, it's available without any sort of judicial oversight to, I don't know, hundreds of law enforcement agencies across the country presents a risk of how it might be used in the future. So it was just a really interesting story. You know, if you look at just my base of knowledge, the state of Maryland, I think our privacy laws at the state level don't account for this type of system.

Dave Bittner: Right.

Ben Yelin: Our data privacy laws don't address retention of mass ALPR data. There is no warrant requirement in our state or in most states for license plate searches. So the only check or balance is the vendor contract. And when the vendor writes the contract and localities are just desperate to fight crime and use these tools to improve their crime statistics, then things can fall through the cracks. So I just found this to be a very interesting story.

Dave Bittner: Yeah, so I have I have a number of questions. First of all, just get this out of the way. Not a fan of Flock cameras.

Ben Yelin: So put them up outside Dave's house, Flock, if you're listening.

Dave Bittner: Well, that's the thing, they are outside. I mean, they have installed them recently. I've noticed they're at the local Home Depot. They're at the local Lowe's at the entrances, multiple entrances of their parking lots.

Ben Yelin: You think about immigration there.

Dave Bittner: Exactly.

Ben Yelin: I mean, there have been all of these raids of people who are day laborers who are standing outside Home Depot looking for gigs. And yeah, I mean, it's very disturbing from that perspective.

Dave Bittner: Yeah, there's another conspicuous set of them that are on the road that is basically right near the entrance to the NSA, which I find kind of hilarious.

Ben Yelin: Right. Yeah.

Dave Bittner: But speaking of that one in particular, you know, you're driving down -- for locals in our audience, you're heading down Route 32 on your way past NSA, and there's a Flock camera set up on both sides of the highway going in both directions. And these things are pretty conspicuous. You can tell they look like themselves and nothing else. There's generally a black pole with the camera mounted to it.

Ben Yelin: Yeah. Once you know what to look for, it's noticeable.

Dave Bittner: Right. Right. So question number one, and I'm not expecting you to know the answer to this. So perhaps it's rhetorical, but if I'm Flock and I want to stick a camera up on the side of a highway, whether it be a state highway or a federal highway, I don't know which one 32 is. I'm guessing it's a state highway.

Ben Yelin: It's state. Yeah. I mean, they can come up with contractual agreements with the state agency that manages the highways.

Dave Bittner: Okay.

Ben Yelin: So it's not just law enforcement, but like the Maryland State Highway Administration can and does contract with Flock to put cameras up there. It's just whomever has jurisdiction over a particular area. So if it's on city streets or town streets, then it's the county or city government, municipal government.

Dave Bittner: But I guess my question, my point is, if I were decided that I wanted to put up Dave's traffic cams, I couldn't just go up to the side of the highway and dig a hole and put one in. I need to get permission, right?

Ben Yelin: Yes. You would need to get permission, just like on any government property, which is ultimately what the roads are. You can't just do whatever you want. You couldn't just like pitch a tent and build yourself a small home on the side of Route 32. I think it's the same sort of principle there.

Dave Bittner: Right.

Ben Yelin: It all has to be done contractually.

Dave Bittner: Yeah. Yeah. So I have concerns about that. Obviously, the privacy thing. But I guess getting at the bigger issue here, Ben, which it strikes me that license plates have become, is it fair to say, a convenient loophole on our civil liberties, because we have to have them.

Ben Yelin: Yep.

Dave Bittner: Driving a car is considered to be a privilege, not a right.

Ben Yelin: That is correct.

Dave Bittner: So here we are, and I don't know a way around this. If, as we've talked about many times, if I know where you live and I know where you work, it's very easy for me to de-anonymize your license plate, which one is yours, who you are.

Ben Yelin: It's even easier with AI, and I think it can be done at scale, where it's not just, okay, we have one or two suspects that we're trying to track their location. It's much more cutting edge than it was even five or ten years ago because of these AI tools that these law enforcement agencies have.

Dave Bittner: So let me lean on your expertise then. How does this intersect with our constitutional right to privacy? What's the argument here?

Ben Yelin: So in order to have any sort of Fourth Amendment protection, it has to be a Fourth Amendment search, right? So the Fourth Amendment protects us from unreasonable searches and seizures. And search in constitutional law is defined in a couple of ways. So one is if the government physically trespasses on your property, which is not the case here when we're talking about license plates. And the second is if the government violates a reasonable expectation of privacy. And basically, our case law has indicated that people don't have a reasonable expectation of privacy when they're on public thoroughfares. It's not within one's own home. It's also not somewhere where somebody takes some type of action that shows a subjective expectation of privacy. It's also illegal in most jurisdictions to conceal your license plate, although people do it.

Dave Bittner: Right.

Ben Yelin: I see it all the time. So you really don't have much of a choice in the matter, which makes it analogous, I think, to a lot of famous Fourth Amendment cases where, you know, in 1979 in Smith v. Maryland, the Supreme Court said you don't have a reasonable expectation of privacy in the numbers, the phone numbers that you dial, because those go directly to the phone company. They're a third party. You don't have a privacy interest over those. But in 1979, like the only method of communication was to use a telephone. So people don't have any type of meaningful choice. Like if you want to participate in society, you have to drive or you have to make a telephone call. So there really isn't any robust constitutional protection here. There are some theories that would impute constitutional protection on something like this. We've talked about the Mosaic theory in the past, where maybe just one data point doesn't invoke Fourth Amendment protection. But when you're aggregating license plate data and you're following the whole of a person's movement over a long period of time, then perhaps that invokes Fourth Amendment protection. But that's not a theory that's really in favor at the current Supreme Court or really in most appellate jurisdictions either. So it's not something, if I were a civil liberties advocate, that I would want to rely on. You know, one really interesting case that I think could have some relevance here is remember those Baltimore spy cameras?

Dave Bittner: Yeah.

Ben Yelin: This was discontinued several years ago. But for a while, the city of Baltimore contracted with a private company. They had an airplane flying at a relatively low altitude, taking real-time photographs every, I don't know, five seconds over an area of downtown Baltimore. The limits were that it had to be sunny out, and they would only be taking photos in the daytime, and people would appear as kind of tiny little dots.

Dave Bittner: Right.

Ben Yelin: And the Fourth Circuit held that this was unconstitutional under the Fourth Amendment. It was moot because we had discontinued the program anyway. But they recognized the Fourth Amendment concerns here just based on kind of the pervasiveness of the surveillance. And that leans on the ruling in Carpenter, where historical cell site location information, that is subject to Fourth Amendment protection because of the depth and the breadth of the information available. So I could see that being applied to license plates, but, you know, it certainly hasn't been applied in the past. And I think you'd obviously get a lot of pushback from law enforcement agencies saying, don't take this tool away from us. Like, this has been so successful in criminal investigations that, you know, you shouldn't extend Fourth Amendment theory to take away this very valuable law enforcement tool. So there are theories that could justify adding Fourth Amendment protection to ALPRs, but I just don't see an immediate future in which that's operationalized.

Dave Bittner: What about just a warrant requirement?

Ben Yelin: Well, I mean, it's sort of the same thing. If there's a search, then there has to be a warrant based on probable cause. But if it's not a search, then you don't need a warrant. So if, and I think most courts at this point would agree that this is, this doesn't qualify as a so-called Fourth Amendment event, then from a legal perspective, it really doesn't matter whether a warrant is required. I think we'd first have to take that first step and say, this is analogous to the evil that our founding fathers were trying to protect us against, which is overzealous government surveillance into our homes and our stuff. And the Supreme Court and lower courts just have not seen it that way. There's not going to be a warrant requirement unless it's done statutorily, which is extremely unlikely, just because this is not at this point considered a Fourth Amendment search, the collection of license plate data.

Dave Bittner: So potential challenges to this, like I could, so two things come to mind immediately. You mentioned someone crossing state lines to get an abortion. I could imagine someone bringing that to -- if someone got charged with having an illegal abortion from crossing state lines and the Flock cameras were used to track them, is it reasonable to think that someone could come after them for that with the Fourth Amendment?

Ben Yelin: Definitely. I mean, that would be the type of challenge you'd see. It would be a challenge to the conviction, and it would be a challenge to the evidence that led to your conviction, saying that this type of search violated your reasonable expectation of privacy. Therefore, a warrant should be required, and in the absence of a warrant, it's an unconstitutional search. So that would be the nature of the challenge. Do I think that challenge, considering current jurisprudence, would be successful today? Almost certainly not, but you never know. You could get a friendly district court judge, and then maybe a court of appeals panel will look at this issue differently and understand the pervasiveness of these license plate reading tools. But until that happens, and that's just something you can't rely on, I think that's why you're seeing local governments say, not in our backyard. Like, we can't wait for the courts to put a stop to this. We have to contractually renege on these agreements or not come to a new agreement with this company to put up more cameras. And I think it's just something where local governments really do have a lot of agency here. You're sacrificing something, and people are going to be really upset when property crime increases and violent crime increases. But it's certainly something within the purview of local governments if they really see this as a threat to the civil liberties of their citizens.

Dave Bittner: Yeah, the other possibility that I bring up from time to time is if someone puts up a website that says, that is like, WhereIsMyRepresentative.org, where you could real-time track your congressional representative.

Ben Yelin: The old video rental store tracker.

Dave Bittner: Yeah, yeah, basically, you know, just demonstrate to the folks who are making the laws how easy these tools make it to reveal their locations.

Ben Yelin: Remember when John Oliver did something similar to that? Was that with cell site location data? I'm trying to remember what the segment was on.

Dave Bittner: He did a very limited version of it. I want to say it was after the January 6th thing, but he's the person I think could do something like this. If he went out, he has the resources.

Ben Yelin: Totally.

Dave Bittner: If he went to a private broker and decided to buy the anonymized data of people coming and going from, let's say, the Capitol building.

Ben Yelin: Yeah.

Dave Bittner: and then use just normal tools to de-anonymize them, which we've said is easy.

Ben Yelin: And much easier with AI.

Dave Bittner: Right. Then perhaps we could get someone's attention, but it's possible that, you know, that sort of stunt is not the kind of thing you want to do under the present administration. So I don't know.

Ben Yelin: Yeah. That would require a sense of shame among members of Congress.

Dave Bittner: Right, right.

Ben Yelin: Which, you know, I don't think that's something you can rely on anymore. It's like, yeah, we followed you to a strip club, and, you know, members of Congress would be like, eh, you know, this guy over here had to quit because he was doing X, Y, Z. A strip club is the least of our problems.

Dave Bittner: Right.

Ben Yelin: So, yeah, I mean, I think in theory that would be the way to effectuate change here. But, like I said, I do think that would require a real sense of shame that I'm not sure that a lot of members of Congress have.

Dave Bittner: Yeah. All right. We will have a link to that story in the show notes. I've also added to our script. We'll put a couple other links in here. There's a website called HaveIBeenFlocked.com where you can put your license plate in, and it'll let you know if your license plate was part of public records. I put my license plate in, and it did not come up, but it doesn't mean -- it basically means it wasn't part of a search that was made a public record. So, it doesn't mean that -- I mean, anybody driving around these days, you're going to be in the Flock database.

Ben Yelin: Right. Exactly. There's no getting around it. I mean, I'm already in a lot of databases because I've violated the speed camera so many times on I-83 South that I'm sure I'm funding the coffers of the Baltimore City and Baltimore County governments.

Dave Bittner: Sure, sure. You're paying your speed tax.

Ben Yelin: Besides that, I would prefer to avoid surveillance.

Dave Bittner: And then the other one is called DeFlock, which is DeFlock.org, and basically that's a map that shows you where all the Flock cameras are in your community. So yeah. All right. I'll tell you what. Let's take a quick break here. We will be right back after this message from our show sponsor. [ Music ] All right. Let's get to my story here. And this is from the fine folks over at LawfareMedia.org. This is kind of a deep dive and a thoughtful look at the whole idea of privatized cyber warfare, sometimes referred to as hacking back, offensive cyber operations and so on. It's a policy debate that's kind of been resurfaced because the White House put out their cyber plan recently in the past few weeks here. And part of that hints at the fact that they may be looking to enable offensive cyber operations from the private sector. And so traditionally, these sorts of things have been handled by government agencies, folks like Cyber Command, and not so much contractors. Although some contractors have certainly been given the ability to do this sort of -- yeah, yeah. But the concerns come from if the government decides to open this up more broadly, what happens? How is there oversight? How do we choose which companies would be able to benefit from this? Who gets to hack back? There's a counterintelligence angle. Once we have these cyber operations are put into contractors' hands, that means there's a greater risk of leaks, of insider threats, of shared infrastructure exposure. We've already seen where spyware vendors get hacked and they get their client lists exposed. So we're expanding the potential attack surface.

Ben Yelin: I mean it's like, it's the same as mercenary armies where the risks are, there is no oversight, it's the Wild West. There's no small-D democratic accountability. It's not as resource-intensive as actually raising a mercenary army.

Dave Bittner: Right.

Ben Yelin: Like you can just have like a few very effective hackers in the private sector, you know, just like we gave the DOGE people unprecedented access to our federal agencies. Like, you get a couple of really, really smart guys who can conduct these operations maybe at the implicit or explicit direction of the administration and do so with kind of full impunity.

Dave Bittner: Yeah, what happens if you have companies offering hacking back as a service, right?

Ben Yelin: Absolutely.

Dave Bittner: And I don't know. It just seems like a big can of worms to me. I understand it at the nation-state level when you're talking about espionage. But on the private sector level, it seems like a different kettle of fish to me. Do you think that's a fair perception?

Ben Yelin: Yeah, I absolutely think it's a fair perception. It's also, you can start to think of the slippery slope here. This would be an escalation in cyber warfare. And when our country escalates, then our adversaries might escalate. So obviously that presents security concerns here in the United States. But if we're unleashing our private sector, like for all of the ingenuity of the U.S. private sector, which is very impressive, like China can deploy their institutional expertise in some ways more quickly than we can and have been prepared for these types of attacks for a long time.

Dave Bittner: And so private sector can't say no.

Ben Yelin: Exactly. That is the difference in China. Now, maybe they can't actually say no here either. But explicitly they cannot say no in China. So, I mean, it certainly presents significant risks. I don't think there's any way you could deny it. But the other thing is, like, what if you are one of these private cyber warriors? Then you yourself might be at risk. You could be treated as, and this is something that the article says, you could be treated as a combatant. So other countries could put out arrest warrants. There could be physical retaliation. It probably means if they find out who you are, there's going to be some type of bounty on you.

Dave Bittner: Yeah. Well, I mean, we're kind of seeing this in the war in Iran right now, where Iran is hitting data centers in neighboring countries that belong to U.S. companies.

Ben Yelin: Yep. And they've been effective at a couple of them.

Dave Bittner: Yeah.

Ben Yelin: They took down a major health care system for an entire, or health care service, I guess, for an entire day last week.

Dave Bittner: Well, AWS lost a couple of data centers and has said they're basically out of commission for the foreseeable future.

Ben Yelin: Yeah. And all of this is, like, escalation ultimately is bad for all of us because, you know, as the attacks get bigger, there's a greater chance that you as an individual are going to be impacted by this once the kind of global cyber war expands. Because maybe you don't use this or that service, but if it becomes so ubiquitous, it's going to start affecting things that you use.

Dave Bittner: This article also points out that international law assumes that nation states wage war. And so if cyber conflict shifts to corporate actors, what does that mean for that framework? I'm trying to imagine this in the kinetic world, you know, if suddenly Microsoft is dropping missiles on somebody.

Ben Yelin: I wouldn't put that past, you know -- no, I'm just kidding.

Dave Bittner: I mean, obviously there's government contractors and all that kind of stuff. I mean, we've seen erosion of standards over the years and decades and centuries. But it's an interesting point. It makes things fuzzier.

Ben Yelin: Yes, it certainly makes things fuzzier. You talk about something like attacking civilian critical infrastructure. So power grids, water services, that type of thing. That would be a violation of international law. But who do you enforce that? First of all, you know, I know a lot of people roll their eyes at international law. I think we should at least pretend that it's something that exists and that we adhere to, because I think it's important to maintain those international norms. But yeah, I mean, what happens if one of these private mercenaries conducts that type of attack? Like, what is the mechanism of international accountability if such a thing exists? I don't think we have any sort of framework for that. And so it kind of lessens the disincentive for a country to not attack critical infrastructure, if that makes sense. If you can pass it off to private cyber warriors to conduct the attack on your country's behalf, and you know that they are going to skirt accountability because we don't have any framework to hold them accountable, then it's more likely that those types of attacks are going to happen.

Dave Bittner: Yeah, I mean, so at this point, it's not that there's any policy in place here to enable this. This is really -- well, it's something that's been in conversation for a long time, for years now. And so I guess the concern is that the White House's most recent statement of their cyber policy aspirations doesn't exclude this sort of thing, and indeed leaves the door open to it, and that's led to interesting discussions like this one in Lawfare.

Ben Yelin: Yeah, and I think it is a brand new world. Like, how are these private organizations going to seek out legal immunity if somebody, if somebody does try to hold them accountable? You know, what is the end result of a global cyber arms race, where we've legitimized cyber attacks from the private sector, so other countries do the same? You know, that expands sabotage operations everywhere. Then you might have private vendors and kind of so-called neutral countries that are selling offensive cyber services internationally, maybe to adversaries to one another. Like, I think it's a world that we haven't really fully conceived of, which is why it's such a good article. I mean, it's such an important issue.

Dave Bittner: Yeah, yeah, and it is a deep dive here. I mean, we've only sort of touched on the surface here, so if this is something that you're interested in, if this is your jam, do check out the article from Lawfare Media. We'll have a link to that in the show notes. It is a good long read, and it is well worth your time.

Ben Yelin: Just because it was published on April 1st does not mean you should take it any less seriously.

Dave Bittner: There you go. Right, absolutely. It's the day to stay off the internet, right?

Ben Yelin: Yeah, I always try to abide by that, and then I forget, and something always gets me.

Dave Bittner: Yeah, me too, me too. All right, well, of course, we would love to hear from you. If there's something you'd like us to consider for the show, please do email us. It's caveat@n2k.com. [ Music ] That is our show brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to caveat@n2k.com. This episode is produced by Liz Stokes. Our executive producer is Jennifer Eiben. The show is mixed by Trey Hester. Peter Kilpe is our publisher. I'm Dave Bittner.

Ben Yelin: And I'm Ben Yelin.

Dave Bittner: Thanks for listening.