25 Years of Mass Surveillance Is Enough - Schneier on Security
Schneier on Security
Menu
Blog Newsletter Books Essays News Talks Academic About Me
Search
Powered by DuckDuckGo
Blog
Essays
Whole site
Subscribe
HomeBlog
25 Years of Mass Surveillance Is Enough This essay was written with Cindy Cohn, and originally appeared in Lawfare. One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in immigration actions and against people exercising their First Amendment rights to protest. It’s also increasingly part of private security systems, such as facial recognition at venues such as Madison Square Garden and networked Flock license plate capture systems on roads and in parking lots. The interrelation between private and governmental mass surveillance is worth examining. Surveillance is the business model of the internet; companies like Google and Facebook constantly spy on their users’ behavior. From the National Security Agency relying on data collected by telecommunication and internet companies, to local sheriffs and ICE agents relying on cellphone location data and privately managed automatic license plate readers, governments primarily obtain the mass surveillance information through private companies. Increasingly, access doesn’t just come through legal processes, either. FBI Director Kash Patel recently confirmed in congressional testimony that the agency is purchasing information on Americans from data brokers and intends to continue to do so. This pipeline from private collection to governmental collection means that as companies collect more information for surveillance capitalism purposes, more is available to law enforcement as well. And as the technology for mass surveillance and analysis improves, especially with the increased use of AI technologies, the problems attendant to mass surveillance grow as well. After 9/11, the idea that the government could surveil the population to safety took hold. In 2001, the fear of terrorism reached a frequency and intensity never before seen. Along with that came the fear that the enemy could be anyone, anywhere. As a result, the government’s response was to watch everyone, everywhere. This line of reasoning underpinned the shift from targeted to mass surveillance. Or, in the words of an internal National Security Agency (NSA) presentation that was made public as part of Edward Snowden’s 2013 disclosures, a government that can “Collect it All,” “Process it All,” “Exploit it All,” “Partner it All,” and “Sniff it All,” will ultimately, “Know it All.” Similar rationales support the rise of domestic mass surveillance: if law enforcement could see and hear everything, it could more effectively interdict and solve serious crimes. The national security community has never provided a full analysis of the costs and benefits of these mass surveillance programs, either in terms of taxpayer dollars or diversion of resources from other efforts—or any demonstration that those techniques stopped attacks that otherwise they would not have been able to prevent. While the NSA occasionally presents examples of the successes due to its mass surveillance programs, especially when those techniques are under public pressure, the examples also regularly fall apart upon serious scrutiny. And even if some utility exists, it must be seriously weighed against the costs. Similarly, there has never been any comprehensive analysis about whether domestic immigration or law enforcement’s use of these techniques actually makes people safer, or whether other techniques could produce the same results. Instead, both the police and the companies selling these tools float anecdotes and dubious data. For example, Flock’s data equates the number of law enforcement hits in their database with actually solving crimes. Twenty-five years after 9/11, it seems reasonable to step back and evaluate the costs of this shift to mass surveillance, especially in terms of Americans’ rights and freedoms. The Shift The easiest place to see a shift to mass surveillance was in the government’s decision immediately after 9/11 to collect Americans’ telephone records. The program started under an argument of pure executive power as the “President’s Surveillance Program.” But in 2006, that argument secretly shifted to a novel interpretation of Section 215 of the Patriot. Act which had only previously authorized more targeted access to record. While some media and public interest organizations struggled to force the government to reveal the program as early as late 2005, the government only officially confirmed it after the 2013 Snowden disclosures. In 2015, the Second Circuit Court of Appeals rejected the government’s interpretation of Section 215 as allowing mass collection of telephone records. Later the same year, Congress passed the USA Freedom Act. While this new law still allows collection of a tremendous amount of domestic telephone records, it ended the indiscriminate mass collection that had occurred for nearly fourteen years. Other shifts to mass surveillance continue through today. The NSA launched its Upstream program, which involved intercepting both metadata and content from key telecommunications junctures inside the U.S., soon after 9/11. It was also initially conducted under a claim of purely presidential authority. This program was brought under marginal congressional and programmatic (not targeted) Foreign Intelligence Surveillance Act (FISA) court review via Section 702 of the 2008 FISA Amendments Act. In 2017, more than15 years after its inception, the NSA ended content searches due to FISA court pressure, but the mass collection continues. Despite the stated goal of conducting mass spying only on people outside the U.S.—which itself is problematic given international law’s requirement that surveillance be both necessary and proportionate—mass surveillance collects a tremendous amount of U.S. persons’ communications. This can happen because people communicate with people abroad, or because of overcollection—when government agencies gather far more personal data on non-targeted US persons than authorized by law. The concerns about collecting Americans’ data on U.S. soil led Congress to allow the program to officially expire in 2026, although the previously-approved mass surveillance itself continues until at least Spring of 2027. The shift to mass surveillance would be notable enough even if it remained only a strategy of the intelligence community. It has not. Americans are awash in mass surveillance. Networks of automated license plate readers such as those offered by Flock and Vigilant Solutions blanket both public and private roadways and parking lots. These networks often allow searches by law enforcement, including across jurisdictions. They are, for example, being used to track people seeking abortions across state lines. Facial recognition tools, once the province of only the more elite parts of federal law enforcement, are increasingly used by Immigration and Customs Enforcement agents on immigrants and protesters, in airports by the Transportation Security Administration, as well as by private entities. And, of course, modern phones track users’ locations constantly—and that information is readily available to law enforcement, often with only minimal process protections. Constitutional Costs Regardless of the murkiness of its actual usefulness, the shift from targeted to mass surveillance has profound implications for Americans’rights. It has created risks that have become increasingly evident, especially under the Trump administration. At a basic level, the Fourth Amendment guarantees that citizens can be secure in their “persons, houses, papers and effects” from unreasonable searches. Warrants breaching that security should be supported by probable cause and particular descriptions of the place to be searched and items to be seized. Mass surveillance turns that promise on its head, allowing access to our “papers and effects” by the government without individualized suspicion or a particularized description of what data is being seized, much less probable cause. This protection was in response to colonial British misuse of writs of assistance, which authorized indiscriminate searches rather than targeted ones. The justifications for exempting mass surveillance from constitutional protection vary. For Section 702, the government has taken the position that U.S. persons’ communications caught up in the dragnet, either due to overcollection or because they were communicating with someone outside the United States, do not require a warrant prior to initial collection or secondary access by the FBI and several other agencies. The argument is that if the initial collection was not aimed at Americans, the information is free from constitutional protection for any later uses, even for reasons far afield from the initial rationale for collection. Other arguments rest on the claim that metadata is outside the Fourth Amendment, despite its demonstrated ability to reveal intimate details of all of our lives. Still others rest on the Supreme Court-created Third Party Doctrine, which holds that the Fourth Amendment does not apply to data shared with companies that provide us with services. Some turn on whether analysis by machine counts, claiming that only “human eyes” matter—a particularly troubling argument with the rise of artificial intelligence. What’s more, the government has used doctrines like standing to limit the ability of those subjected to mass surveillance to seek constitutional protection. No matter the argument, the goal is the same: to place the mechanisms and fruits of mass surveillance outside the protections of the Fourth Amendment. The overarching truth is that, due to the concerted efforts by the government since 9/11, and the rise of technologies in recent years, the slice of Americans’ lives and data that are actually protected by the Fourth Amendment has shrunk significantly in the past 25 years. Together, with the technical capabilities of mass surveillance and the increased ability for that data to be analyzed using AI tools, the “security in our papers and effects” that the constitution promises seems increasingly illusory. In addition to the Fourth Amendment, mass surveillance creates tensions with the First Amendment. The Constitution has long recognized that the right to freedom of speech requires a zone of privacy against governmental surveillance. The right to anonymous speech as well as the right of association both recognize the chilling effect that surveillance creates for people saying unpopular things or attempting to organize for political or other societal change. Mass surveillance grants the authorities the ability to track those people, both in real time and historically, that is inconsistent with actual techniques of freedom of speech and assembly. That is why the recently released 2026 U.S. Counterterrorism Strategy is so troubling. On page seven, the White House expressly states that it intends to target domestic activists with its heretofore foreign-targeted powers. It says that the government “will prioritize the rapid identification and neutralization of violent secular political groups whose ideology is anti-American, radically pro-transgender and anarchist” and “will use all the tools constitutionally available to us to map them at home, identify their membership, map their ties to international organizations like Antifa.” While framed as targeting “violent” groups, it’s clear that the government intends to use its national security tools, presumably including the tools of mass surveillance, against Americans in ways that will create profound tensions with the First Amendment rights of people to organize and communicate privately. Costs Due to Mistakes and Abuse Even assuming some utility from mass surveillance—a fact we do not dispute, even if the public record is shaky and conclusory—the history of both the national security and domestic uses of mass surveillance confirms that these tools are inevitably misused, and that mistakes have impacted huge numbers of Americans. The past twenty-five years have demonstrated that it is not possible to surveil the entire US population while staying within the bounds of even a very generous legal framework like Section 702. As Rep. Zoe Lofgren (D-Calif.) recently stated in discussion of Section 702 in an interview with Tech Policy Press: “backdoor searches have been used improperly for protestors, 19,000 campaign donors, members of Congress, journalists, government officials, a state court judge who had complained to the FBI about police misconduct. It has been abused substantially in the past.” The NSA experienced so much abuse of its mass surveillance tools by actual or aspiring romantic partners and ex-spouses that an internal name emerged for it: “LOVEINT,” or Love Intelligence. That same pattern of abuse is now emerging at the domestic law enforcement level. A Texas police officer misused, and then lied about, using license plate readers to track a woman suspected of seeking an abortion. Multiple law enforcement officials have been accused of tracking people they either wished to have a relationship with or who were their exes. And mass surveillance technologies have been used to track both immigration targets and citizens engaging in their First Amendment-protected right to track and record the police. Mistakes are inevitable with collections of data of this size and scope. The history of the FISA court’s reviews of Section 702 is littered with examples of the NSA not being able to follow its own rules limiting the scope of what it collects and analyzes, even after having been given multiple chances by the court. On the local level, the technical protections that Flock, for example, put in place have repeatedly been insufficient to stop “accidental” sharing its data with out-of-state law enforcement. These mistakes have fueled growing efforts by local communities across the country to remove license plate readers. Those efforts should be the first step in a broader reconsideration of mass surveillance. More generally, ubiquitous surveillance carries a real societal cost. The chilling effects are real and pervasive, and they tend to fall hardest on the most marginalized members of society. Moreover, social progress requires the ability to experiment in secret. It’s hard to imagine a society progressing morally to the point of accepting and legalizing things like marijuana use or gay marriage if the earliest signs of that shift are snuffed out because of overzealous surveillance. Reversing Course While a cost-benefit analysis is not the best frame for deciding constitutional rights, it is a place to start to evaluate government policies. If the costs are too high and the benefits too small, what should the public do? While the policy and legal frameworks can be individually complex, mass surveillance is a problem in all of its applications. So too should solutions be comprehensive rather than piecemeal. One comprehensive strategy is to reset the promise of the Fourth Amendment and recognize that a warrant is required prior to collection, access or use of information gathered through mass surveillance. This would apply to collections that include U.S. persons, whether done for national security or domestic purposes. This protection would apply regardless of whether the information is in the form of metadata. It would apply regardless of whether the information is held in homes or by services people rely on, such as telephones, internet or social network providers, or by private entities utilizing mass surveillance for their own purposes. By passing this legislation, Congress could ensure this rejection of mass surveillance, and include real enforcement such as a private right of action and an automatic exclusionary remedy in criminal prosecutions. The courts could also recognize this protection of “papers and effects” directly as a plain language interpretation of the Fourth Amendment. There are already a number of efforts that take on pieces of mass surveillance. Section 702 has expired and should remain so. This was due largely to efforts to block the “back door” access to Section 702-collected data without warrants. The bipartisan “Fourth Amendment is Not for Sale Act” would prevent the government from purchasing data that it would otherwise need a warrant to obtain. The Supreme Court itself has already been chipping away at the Third Party Doctrine, with a recent step in the rejection of mass geofence warrants—warrants seeking the identities of individuals based upon their proximity to a crime—in Chatrie v. United States. Now, such warrants fall, at least initially, under the Fourth Amendment. A more comprehensive approach would also address mass surveillance carried out by private companies, and to ensure that Americans have the right to encrypt and secure their data. There are many reasons the United States would benefit from a comprehensive privacy law—and curbing mass surveillance is one of them. Addressing mass surveillance is certainly one of them. Ideas such as the banning of secondary uses of data—with roots in the Fair Information Practice Principles from the 1970s—are worth pushing forward. So are moves such as creating fiduciary duties for mass data collectors. There are many more ways to curtail private companies’ mass surveillance while staying within constitutional boundaries. But addressing the costs of mass surveillance by both companies and governments is even more important in a world where AI agents are making decisions both about the public and on their behalf based on their data and observed behavior. Twenty-five years after the U.S. government embraced mass surveillance, it’s time to evaluate it as a whole, and consider responses that address the problem as a whole. Americans must ask: Is it consistent with a self-governing democracy to have systems that watch everyone everywhere? Is the public comfortable with governments—federal, state, local—that seek to “know it all” about its citizens? Is the public comfortable with private mass surveillance in its own right and as it’s being increasingly used to fuel government surveillance? These questions have long needed serious consideration. But as it becomes increasingly evident that the Trump administration is using mass surveillance to keep itself in power, stifle dissent, and undermine political opponents, these questions are now more urgent than ever.
Tags: privacy, surveillance
Posted on September 15, 2026 at 7:01 AM • 2 Comments
Comments
TimH •
September 15, 2026 7:51 AM
Sorry Cindy, and I much appreciate your work at EFF, but the last paragraph is nonsense. “Americans must ask…”, “Is the public comfortable with…” indeed. The citizens have no agency to change any of this.
Jon •
September 15, 2026 9:43 AM
Thank you.
Subscribe to comments on this entry
Leave a comment Cancel reply Blog moderation policy LoginName Email URL: Remember personal info?
Fill in the blank: the name of this blog is Schneier on ___________ (required):
Comments:
Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/
Notify me of new posts by email.
Δ
← On the NSA’s Supercomputer from the 1960s Sidebar photo of Bruce Schneier by Joe MacInnis. Powered by WordPress Hosted by Pressable
About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998. I'm a fellow and lecturer at Harvard's Kennedy School and the Munk School at the University of Toronto, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc. This personal website expresses the opinions of none of those organizations. Contact Info Related Entries
Automobile Camouflage to Hide from Flock CamerasWireless Routers as Motion DetectorsSpyware for BabiesAdversarial Clothing Designed to Fool Facial Recognition SystemsFacial Recognition at Madison Square Garden
Featured Essays
Four Ways AI Is Being Used to Strengthen Democracies WorldwideThe CrowdStrike Outage and Market-Driven BrittlenessHow Online Privacy Is Like FishingHow AI Will Change DemocracySeeing Like a Data StructureLLMs’ Data-Control Path InsecurityAI and TrustThe Value of EncryptionThe Eternal Value of PrivacyTerrorists Don't Do Movie Plots More EssaysBlog Archives
Archive by Month100 Latest Comments Blog Tags3d printers9/11A Hacker's MindAaron Swartzacademicacademic papersaccountabilityACLUactivismAdobeadvanced persistent threatsadvertisingadwareAESAfghanistanAIair marshalsair travelairgapsal QaedaalarmsalgorithmsalibisAmazonAndroidanonymityAnonymousantivirusApacheAppleMore TagsLatest BookMore Books
Blog Newsletter Books Essays News Talks Academic About Me |
The shift in government surveillance following the September 11th attacks involved moving from targeted surveillance, such as individual wiretaps, to mass surveillance techniques like tapping into the internet backbone and the mass collection of telecommunication or internet metadata. This legal and technical architecture has expanded far beyond initial justifications of national security, becoming a routine tool for law enforcement, used in immigration actions, and integrated into private security systems like facial recognition and license plate capture. This situation is compounded by the relationship between private and governmental surveillance, as companies like Google and Facebook function as the business model of the internet, collecting vast amounts of user behavior data, which governments subsequently obtain through these private entities. This pipeline means that as private companies amass data for surveillance capitalism, more information becomes available to law enforcement, and the efficacy of these programs is further amplified by advancements in surveillance technology and artificial intelligence.
The rationale for this shift was rooted in the post-9/11 belief that the government could surveil the population for safety, leading to the idea that a government capable of "Collect it All," "Process it All," "Exploit it All," and "Partner it All" would ultimately "Know it All." This logic supported the expansion of domestic surveillance. However, the national security community has failed to provide a full analysis of the costs and benefits of these programs in terms of public resources or demonstrated success against attacks. Anecdotal data from agencies and corporations often floats over comprehensive analysis and demonstrates that these techniques do not necessarily prevent attacks.
The evolution of mass surveillance includes specific legal and operational shifts. Initially, the government sought to collect Americans’ telephone records under the guise of executive power, but this evolved through interpretations of the Patriot Act and subsequent court rulings, such as the rejection of mass collection in 2015 by the Second Circuit Court of Appeals and the passage of the USA Freedom Act, which ended indiscriminate mass collection. Further changes include the NSA's Upstream program and the continuation of mass collection despite efforts to limit content searches. Despite stated goals of targeting non-U.S. persons, this mass collection captures a tremendous amount of U.S. persons’ communications, often resulting from overcollection or the gathering of data on U.S. persons on U.S. soil. Today, this shift is evident in widespread technologies like automated license plate readers and facial recognition systems used by agencies like Immigration and Customs Enforcement and private entities, alongside constant location tracking through modern phones.
This shift has profound constitutional costs, primarily challenging the Fourth Amendment's guarantee of security in "persons, houses, papers and effects." Mass surveillance undermines the principle that warrants require probable cause and particular descriptions, allowing government access to personal data without individualized suspicion. Arguments exist to exempt surveillance, such as the claim that metadata is outside the Fourth Amendment or reliance on the Third Party Doctrine, which posits that the Fourth Amendment does not apply to data shared with service providers. Furthermore, the use of machine analysis raises concerns about the role of human oversight, while the government has employed doctrines to limit the ability of individuals to seek protection. Consequently, the extent to which Americans' lives and data are protected by the Fourth Amendment has significantly diminished over the past twenty-five years, especially when combined with advanced AI analysis.
Mass surveillance also generates tensions with the First Amendment. The constant tracking capability creates a chilling effect on freedom of speech and association, hindering individuals from expressing unpopular views or organizing political or societal change. This tension is particularly relevant when considering policies that aim to target domestic activists, suggesting the use of national security tools against citizens engaging in First Amendment-protected activities.
The history of these programs is marked by documented abuses. The misuse of surveillance tools by both national security agencies and domestic law enforcement has resulted in mistakes and serious impacts on Americans. Reports indicate improper use of backdoor searches, some of which targeted protestors and public figures. Similarly, law enforcement has faced accusations of misusing license plate readers against individuals, and surveillance technologies have been used to track both immigration targets and citizens exercising their rights. These historical errors highlight the necessity for a broader reconsideration of mass surveillance.
To address these systemic issues, a comprehensive approach is necessary rather than piecemeal solutions. This approach should seek to reset the promise of the Fourth Amendment by mandating warrants for the collection, access, or use of information gathered through mass surveillance, regardless of the data form or location. This protection should extend to all U.S. persons, irrespective of whether the information is metadata or location data held by private service providers. Furthermore, addressing mass surveillance requires tackling the responsibilities of both governments and private companies. This involves implementing measures such as banning secondary uses of data, establishing fiduciary duties for data collectors, and ensuring Americans have the right to encrypt their data. Ultimately, confronting the costs of mass surveillance requires answering fundamental societal questions about the legitimacy of systems that seek to "know it all" and ensuring that the pursuit of security does not erode core democratic rights. |