DHS Refuses to Back Away from Invasive Spying at the Border
Back in March, CDT, along with more than 50 other civil society groups and trade associations, wrote a letter to Department of Homeland Security Secretary John Kelly urging that he back away from DHS proposals to use border searches as a tool to collect passwords and other social media information. Today we received a response. Unfortunately, the reply largely ducks our concerns, ignoring the main issues at play and doing little to shed light on the government’s plans or put to rest controversy about its contentious proposal. This non-answer is deeply troubling because it seems to indicate that Customs and Border Protection (CBP, which is a sub agency of DHS) is doing nothing to change course from a recent, dangerous trend: the use of the U.S. border as a tool to conduct broad surveillance.
To understand why this is a big deal, we need to look at two things: the law at the border and trends in technology. When you enter the United States, your privacy rights are at their lowest point – the government can search you and your belongings, detain you for questioning, and, if you are not a U.S. citizen or lawful permanent resident, bar you from entering the country altogether.
This legal reality has always made for some uncomfortable privacy issues (strip searches are sometimes authorized at the border!), but our digital lives have supersized these issues. We now carry much more information about us – our political views, reading habits, and professional documents – in the form of mobile phones that are, like any other piece of property, subject to search. Worse, the government has started to leverage its immense border power to force disclosure of social media identifiers and passwords, which can be used to track travelers and invade their privacy even after they pass through the border.
The Obama administration started this trend. Back in 2009 DHS approved a policy that allowed any laptop to be searched without restriction. This policy remains in force today in spite of at least one appellate court ruling that some criminal predicate is required for a search and the reality that many more people travel with personal devices. The Obama administration also took the first steps toward requiring disclosure of social media information. In spite of widespread opposition and a lack of evidence that the information has value, they created a voluntary process for some visitors to declare their social media handles.
The Trump administration has doubled down. Secretary Kelly has promulgated proposals to collect not just social media identifiers but also passwords. The voluntary collection of social media identifiers has been extended to visitors from China, and identifiers and passwords would be required as part of so-called extreme vetting of visitors from six majority Muslim nations. CBP also seems to have ramped up use of the policy, dramatically increasing the number of phones searched and also singling out particular groups, including Muslims and foreign journalists.
These trends are certain to result in privacy invasions, excess government scrutiny, and harm to cybersecurity. It is likely that other nations around the world will move to adopt these same rules as well. As we told DHS back in March, the practical result is that border crossing will require full digital disclosure – exposing not just our personal information but also the tools we use to bank, communicate, and participate in our digital lives. This will not just infringe on free expression and privacy, but will also expose our personal information to the federal government who has a terrible track record of keeping such information safe. Ironically, it’s unlikely to have any security value, since bad actors conceal their accounts and the government drowns in information from innocent people.
So what can we do? First, Congress can continue to demand more information including how many device searches are happening (data on government searches is notoriously hard to get in this area). The confirmation hearing of a new CBP head would be a great place to start. Congress can also push to make DHS clarify the limits of its authority. Senator Ron Wyden recently forced CBP to admit that it does not have the authority to search cloud-based accounts that are linked to mobile devices. Finally, Congress must act – members should endorse the bipartisan Protecting Data at the Border Act to reign in invasive border practices.
CDT-led Coalition Calls for Transparency for White House AI Framework
CDT and Americans for Responsible Innovation led a broad, bipartisan coalition of over two dozen civil society groups in calling on the White House to release its Framework for review of frontier AI models.
CDT Amicus Brief Calls on Fourth Circuit to Rein In Geofence Warrants
Earlier this year the Supreme Court ruled in Chatrie v United States that the Fourth Amendment protected all cell phone location information, which CDT lauded as a landmark decision, but sent the case back down to the Fourth Circuit to assess the propriety of the geofence warrant at issue.
CDT and Partners Post Floor Alert Opposing CA SB 1013 Automated License Plate Readers Bill
The best way to ensure that Automated License Plate Readers are not abused is to limit the retention of stored data and to keep loopholes to lawful process closed. CA SB 1013 is a step in the wrong direction, and we urge the California legislature to reject this approach.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.