📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

They hide secret code in your apps

Naomi Brockwell TV1:02:25

Transcription

Governments buy up large amounts of data, even if they're bulk surveillance programs, even if they're on everyone or vacuum up every single line of data that's out there and available for sale. A lot of this takes place in the shadows. These companies that collect data, their clients sell it, and then their clients sell it. And the next thing you know, it's part of a government surveillance program.

The Constitution was written before modern technology, and this doctrine that if you share something with a third party, you've lost your core Fourth Amendment protection on it is very, very outdated. The way that apps work, you basically have to share everything with a third party. It's not realistic to allow anyone, including government agencies, to just buy this data and say they've lost their privacy interest in it.

I'm sorry. We can't have a public conversation about changing social norms if this stuff remains hidden. Really delighted to have on the show today, Byron Tau. He's the author of Means of Control. He is also a reporter at the Nonprofit News Outlet NOTUS. Welcome to the show. Thanks for having me.

So I was absolutely fascinated by your book. I read it twice and I took extensive notes. And I actually think that it's a must-read for people to kind of contextualize how data collection has evolved and what people need to be aware of when they're using modern technology. 'Cause I think we do a lot of things that are uninformed, and that needs to change.

So just talk to me a little bit about what your book is about and what drove you to write it. So, at the highest levels, my book is about all of the ways in which governments are increasingly buying data, not using, you know, traditional court orders or wiretaps, but just going out into the market and purchasing it from data brokers.

And I got a tip about probably five or six years ago at this point that the Pentagon was acquiring large amounts of location data through these contractors in the DC area. And I thought that was pretty extraordinary. You know, I thought I knew my way around technology. I thought I knew what my phone did. Um, but you know, the weather app or the game on my phone as a vector for government surveillance was something that I just hadn't considered.

And so, uh, I started digging into this world at first quite slowly and with great difficulty. But as I started to understand, uh, how data brokers worked and how they had relationships with the government, uh, it became easier and easier. And I saw that this was a broad phenomenon that went beyond just, uh, you know, weather apps and games providing this data, but was a real, uh, enduring phenomenon of governments turning to data that's out there and available for sale, uh, as a surveillance tool and as a way of understanding the world and keeping tabs on the population.

And talk to me about why they might be resorting to purchasing data in the US. We do have constitutional protections that are meant to stop the government from going through all of our information without a warrant, and yet the current reality is so far removed from that.

Yeah, I think it's, uh, for a variety of reasons. Um, I think part of it is just the amount of data that we generate every day. And the fact is that companies increasingly have started to see that data as a resource, as a, uh, tool, as a commodity in many ways, and are making it available for sale, for targeted advertising and for analytics and for research purposes.

And the government is sitting there and saying, you know, our mission is so much more important than whatever Home Depot is doing with it, or whatever Starbucks is doing with it. So why shouldn't we acquire the exact same data sets that these companies are using? And, uh, lawyers have by and large blessed this because in the United States, generally speaking, when we share information with a third party, courts have generally tended not to recognize a privacy interest in it, right? There's no longer that Fourth Amendment protection.

And so lawyers have by and large signed off on these programs where governments buy up large amounts of data, even if they're bulk surveillance programs, even if they're on everyone or, you know, vacuum up every single line of data that's out there and available for sale. The way that the government phrases it is whether we have a reasonable expectation of privacy.

But if you ask the average person, do they think that using this app is going to betray the most intimate details of their lives, they're all gonna say, no, I want that information to be private. So I feel like there's some semantic juggling going on. If one party involved says, no, I reasonably expect that this information is gonna be private, and the other party says no, if you hand it over to a third party, you have no reasonable expectation of privacy.

And it's particularly chilling for me in the internet age where everything relies on a third party. 'Cause we're essentially saying we can no longer have private lives. I think that's right. I mean, I think the Constitution was written at a time, uh, before, you know, there was modern technology. And that this doctrine, this notion that if you share something with a third party, uh, you've lost your core Fourth Amendment protection on it, is very, very outdated.

Because the way that modern telecommunications work, the way that, uh, modern internet services work, the way that apps work, you basically have to share everything with a third party. Uh, you have to share your location to get an Uber ride or to have delivery. You have to share all sorts of information to get on the internet about your device and your IP address.

And so it's not realistic, uh, to allow anyone, including government agencies, to just buy this data and say, well, you know, people have just handed it over to their ISP or this random app. And so they've lost their privacy interest in it. I'm sorry, this is somewhat of an outdated notion, and I don't think our laws, our norms, and our sort of jurisprudence have caught up to this reality.

People have a sense that everything's being collected, but it kind of happened gradually. And identifying like the different stages that we went through to get where we are today, I think can be helpful for people to contextualize this journey. I basically categorize them in four separate generations.

And the first generation is the original generation of data brokers. They came out of the 1960s and at first they were doing very basic demographic stuff, right? They were collecting information about address history or some stuff down at the courthouse like your marriage certificate or your hunting license. Eventually, these companies, which include, um, names like Axiom and, uh, TransUnion today and, uh, Sizent and ChoicePoint, they branched into doing a little bit more consumer stuff.

They would sometimes buy magazine subscription records and they would say, well, what can we tell about you from the fact that you subscribed to Golf Digest or Dog Fancy or something like that? Then they really got involved in government projects a little bit after 9/11 around identity and who's boarding an airplane. In some instances, they were sort of dragged into trying to hunt down people with, uh, connections to terrorist groups abroad to try to find their addresses.

But as things changed, as technology changed, as social norms changed, there started to be different kinds of brokers brokering different kinds of data. And so, uh, the second generation of data brokers that I focus on is social media data brokers. So when social media became a very big part of everyone's lives, people started tweeting, people started posting things on Instagram, on Facebook, uh, these brokers sprung up to essentially collect data on those social networks and provide them to companies.

Um, because often brands wanted to know what people were saying about them. Uh, news outlets wanted to know what people were saying about the news, or if there was a breaking news event. And eventually governments figured out that criminals were on these networks, that terrorists were on these networks, and they started buying that data.

Then we get into the data sets where you had the Pentagon buying mobile phone data, uh, that was generated from apps because as mobile phones became a much bigger part of our lives, governments realized and companies realized that there was all sorts of analytics and mobile data coming off of those devices and that that was available for sale.

And so that's sort of a generation of location data brokers or mobile advertisers. And finally, uh, there is this weird esoteric world of what I call gray data. And it's essentially data that's just out there for the taking. It's a byproduct of using modern consumer technology.

So there's certain kinds of internet data out there that you can purchase called NetFlow data or DNS data, very, very technical, but it can show some information about computers connecting to one another and where they're browsing on the web. Another example of gray data is just all this wireless data. You know, you and I think are both AirPods and those AirPods are constantly looking for other things, other devices to connect to, but they're also screaming out an identifier at every point.

And if you are a spy agency or a company and you, uh, have a radio that can listen for those transmissions, you can start to map them around the world and potentially track people that way. So those are the four generations of data brokers that I really catalog in the book.

You talked about how government's impetus for getting involved is kind of around terrorists and people doing heinous crimes. So I think a lot of people are gonna listen to this and say, well, why is that a bad thing? I want the government to have information about bad people so that they can keep us safe. Talk to me a little bit about why collecting all of the data of every innocent American in the country in order to, you know, catch some bad people is actually really bad for society.

I think Americans in general are quite skeptical of bulk surveillance programs, right? I think everyone understands that if there's a criminal or a crime, uh, and uh, the police or investigators want to search their device or they want to look at camera footage or something, that's a reasonable, uh, thing to let government do. And you generally have judicial oversight.

You know, the prosecutor has to go before a judge, get a search warrant, they go into your house, they search your papers, they take your phone, they take your computer. That's the traditional understanding in every one of these programs that I've, uh, written about. This is a, a form of bulk data collection. It's a collection on everyone in the United States.

We tend to protect privacy, uh, by limiting the amount of information that the government gets about us. And these programs start to challenge that idea of limited government and of limiting government. And, you know, some people say that, well, perhaps the social bargain is being revisited or revised.

And, uh, in exchange for all these free services, we all just have to accept and understand, uh, that what comes along with it is intru-- increasing or intrusive surveillance. And that may be an argument, but it's not one that I think is being had openly. I think a lot of these companies that collect data are being somewhat sneaky about it.

I think that government entities are not explaining fully to the population what they're collecting and why they're collecting it. And so we can't have a public conversation about changing social norms if this stuff remains hidden. Americans traditionally are very skeptical about these bulk surveillance programs, and that is what essentially these are, uh, they're bulk access to data about the population.

In some cases the US population, in some cases the global population. And in general, we as a society have tended not to like going down that road. I have a lot of conversations with people where they say they don't worry about this because why do they care if Nike is gonna target them with a nicer pair of shoes or something.

And they kind of break it down to the most innocuous use of this data. But talk to me about how this data is actually being used for more kind of insidious purposes. Essentially, when a company at the point of collection tells you that it's for corporate uses or it's anonymized, or there's no personally identifiable information included with that dataset, that often isn't true.

Uh, they are often not being upfront about the purpose of the data collected because they can't guarantee what's going to happen to it if it's, uh, sent into this economy of data brokers and data aggregators. They can't guarantee that a government entity or a private investigator or even a foreign adversary like Russia or China is the buyer of these data sets.

And then second on the anonymity piece, you know, yes, it's true that there's no name or phone number attached to a lot of these data sets, especially about mobile phones or about Bluetooth headphones. But if you are a determined enough adversary, there's some basic tradecraft you can do to figure out who a person is.

So, I mean, I live in Washington DC. I live in the Capitol Hill neighborhood. Uh, I'm the only person that wakes up at my residential address and bikes down the National Mall to my, uh, workplace here in Georgetown, uh, across the city. Even if there's no name attached to my geographical location. If you had a dataset of all the devices moving around Washington DC and you knew where I lived and you knew where I worked, you could pick me out of that data set.

And so oftentimes, uh, people are not being told the truth at the point of collection or in the terms of service to the extent they even bother to read those things about what could happen with their data and what the actual privacy risks are of collecting it and, uh, possibly sharing it. The companies that are actually doing good things will explicitly tell you, I will not sell your data.

We will not share your data. We will not sell your data. Like you'll have it in very clear terms. If there's anything less than that, you should be really skeptical about what's happening with your data because they use a lot of squishy language that basically allows 'em to do anything, Right.

If you read these privacy policies, and again, nobody does, but if you do, if you're a journalist like me or you're a privacy advocate and journalists like yourself, you can see that oftentimes the uses are quite broad. They'll say to fight fraud for analytics. They may reshare it with partners who may do those things as well.

And once, uh, you know, you have a collection in terms of collection that broad, there's no way any of these companies can ever really tell you what happens to it. A couple of hops down the line because, uh, you know, their clients sell it and then their clients sell it. And the next thing you know, it's part of a government surveillance program.

These terms of service, unless they say something very explicit like we never share with any third party, uh, then you really can't know what's happening to your data after it leaves your device. A lot of people still exist in a bygone era where private entities and government entities are distinct and separate.

You know, once upon a time, if you went to a brick and mortar Blockbuster store or your local video rental place, they might collect your name and phone number, contact number, and that would stay on their local system. And if a government wanted to know your history of movie watching, which is the only thing they could get from these records, then they'd have to subpoena that specific organization.

So it was like this big barrier between our private information and it ending up in the hands of government. And today, first of all, the lines between government and private are really blurry because all of the information that we're handing over to these private companies, it's all being purchased by governments.

And so we just no longer have that distinction. And on top of that, there's far more information being collected by businesses than in traditional brick and mortar days. That's entirely true. And it's funny you bring up video stores because a fun fact is there actually is a law that bans Blockbuster from sharing your video rental history because in the 1980s, a nosy journalist went to go get a Supreme Court nominee's video rental history, and Congress thought this was appalling and put a statutory protection in place to make sure that nobody could do that.

But they haven't done anything like that when it comes to the data that modern services collect and what those services collect goes far beyond your video rental history, right? I mean, uh, just moving around the web, uh, generates all sorts of records that your telecom has, uh, on you or potentially a company like Apple and Google and whoever's running DNS servers.

So there's numerous companies that are in positions to collect that. There's hundreds of thousands of entities that could potentially get information about your device, including some very highly technical information about your device. You know, cars today, they broadcast all sorts of data into this shadowy ecosystem.

And it wasn't until the New York Times dug into where GM data was going that we got a pretty good and ugly look at how many data brokers and how many other parties were getting data surreptitiously off of automobiles. And so the reality is that modern services are so much more data intensive than anything a brick and mortar store had, and that our legislators have simply not done anything that would enact anything like a privacy protection or a barrier to government gaining access to it.

So essentially we live in a world that is kind of the wild west. And if you translate that statutory protection from video rental places to the modern world, I don't even think we have anything in place to protect the digital version of that today. Like I don't think that Netflix is being bound by that. They're probably selling our rental history of things that we're watching there.

Uh, Amazon is probably doing the same thing. Apple TV is probably doing the same thing for advertising purposes. So we haven't even taken very explicit protections that have historically existed and applied them in very clear-cut cases to the digital equivalent. Stuff I watch on YouTube seems to either generate ads or at least it's used as part of an algorithm to show me more stuff across various platforms.

And so, yeah, it doesn't seem like there is a tremendous amount of respect for these sort of precedential decisions that existed in more analog versions of these laws. I wanna understand how we can start to push back as a society, and the first step to that is getting people to care.

Yeah, I think there's just a lot of cynicism and even nihilism about privacy. You know, I think people like it in theory, but when it comes down to it, they find it very confusing, especially older folks who don't fully understand how their devices or systems work. It seems to them to involve a lot of technical skill that they may or may not have.

And so I think people by and large give up where they feel very helpless or they don't know where to turn to. And I think that, you know, YouTube channels like yours that offer very straightforward guides about the threats and what to do about them are actually somewhat empowering. And there are many other such resources on the web, but they haven't penetrated to a sort of a mass audience in the way that I think would be important to reverse some of this.

But I, you know, I do think increasingly in society privacy is part of, uh, a broader conversation. I think the TikTok stuff is a pretty, uh, wild example of privacy and content rising to this level of a national discussion about it. I do think the Dobbs decision in a lot of ways was a moment where a lot of people started paying attention to data privacy, especially if they were living in a state where abortion suddenly might become unlawful and that they were fearful that their state government might try to stop them from traveling to a different state.

Suddenly data, data privacy concerns were, uh, very much at the forefront. And I think, uh, increasingly we are seeing real legitimate harms from some of this data collection, whether it's all these data breaches that affect nearly every service or people being scammed, uh, by scammers or criminals or in some cases nation states.

So I do think, uh, there is a growing awareness and, you know, it's entirely possible that we may be at a tipping point as a society where more regulators and more ordinary people start to pay attention to this stuff. I wanna talk about some specific organizations that you mentioned in your book because it takes it from this abstract concept of data brokers are doing things to, here is a company, this is what they're collecting, this is who they're selling it to, it becomes very real.

Babel was one that was really at the forefront in your book. What is that? Yeah. So Babel Street, uh, came out of a data broker called Acxiom. It was founded by some folks who had experience in naval intelligence and other government intelligence agencies. And they were founded essentially as a social media monitoring tool.

But they also had this very, uh, interesting language capability because their idea was essentially that, well, a lot of social media is in other languages. You are an analyst sitting in the Pentagon or at some forward operating base somewhere you actually might need to search the same word across multiple languages if you want to do your job.

And so what they built was this whole taxonomy of how to search, uh, multiple social media sites, uh, including things, uh, that aren't traditionally thought of as social media sites like Backpage or keywords or phrases and, and build sort of searches, uh, around these things. So you could try to figure out what's going on.

But essentially they started branching out more and more into, uh, being a more all-purpose tool. And they started integrating these location data sets into their product. And, uh, essentially they had a now a phone tracking capability that went along with their social media monitoring.

And they were for a long time, a pretty big vendor to a lot of government agencies. You know, uh, this world changes pretty rapidly. I mean, they still exist. They still, um, have a fairly large FBI contract for social media monitoring, but there's all sorts of new tools that do the same thing and integrate AI and machine learning into their workflows or whatnot.

But it's one of many of these vendors out there that pop up and, uh, cater these data sets to government, including the military, including intelligence agencies and including police officers in many cases. This was an industry that I didn't realize was so big. Just the number of companies, data brokerage, uh, firms that are just government contractors, a lot of them are completely unknown to the general public.

Uh, they're all based in, you know, anonymous, faceless office parks here in the Washington DC area. They exist to cater to this government appetite for data. Often they're actually pretty small companies, you know, they'll do a couple million or maybe, you know, 10 or 20 million in revenue. They'll have a couple dozen employees.

Um, but they broker large amounts of data on the global population to government agencies. Many of them specialize in the American government, but there are equivalent, uh, foreign tools, or sometimes the same entities will sell to our closest allies like the British and the Norwegians and, you know, the French and all that.

There's this giant market for these, uh, brokers or, uh, in many cases they wouldn't call themselves data brokers. They would say they're selling a, a tool or a solution to the government, but essentially they're a broker. It's an innocuous solution, isn't it? We're a solution broker! Yes, you have a problem, we have a solution.

Yes. Um, but essentially that's what they're doing. They're facilitating access to data sets that they're licensing or they're acquiring and they're providing it to government entities. I, to me, that's a data broker. They're specializing in and selling access to data.

When you add up all the money that these defense contractors and these government agencies spend, it's pretty substantial. There's some self-awareness that what they're doing is not ethically sound because they'll say things like, oh, well you are not allowed to talk about us if this information ever comes up in a court case.

You can't talk about how you got the information. You can't mention our contract at all. Like, it's a very secretive world. Talk to me about that. So Babel Street was one such company when they introduced this location product, they basically said to government agencies, Hey, listen, you can never mention this in court records.

Um, part of that I think is because they didn't want the public scrutiny that went along with it. But the other part of it is, honestly, I don't think they can vouch for the data if they were put on the stand, right? I don't think they would be able to tell you where the data came from. They'd say, well, we licensed it from another company and where they got it from, you're gonna have to call them in here.

And then, you know, the same thing would happen if you called that company in. You know, they'd say, well, we license it from another company. And so part of it is 'cause they just can't vouch for the providence of it. It comes through this maze of contractors and resellers and aggregators.

And so they just don't want the trouble of explaining to the public or a judge, uh, exactly where their sources are and where it came from. This kind of turtles all the way down, right? Except it's data brokers all the way down, data going from agency to agency to shell corporation to shell corporation.

It's, uh, underground worlds that you really illuminated in your book. Both the companies themselves, because I think they realize that consumers find it a little bit distasteful when they're given a, a very exacting look at exactly what's happening with their device data and their browsing data.

And also the government. I think neither of these forces in our lives want to talk about this stuff because, you know, for the government, they don't want adversaries to realize what's going on. Uh, they don't want criminals to switch their tactics or leave their phones behind.

And so a real public conversation about a lot of what's happening in technology and in law and in government is absent because these vendors, uh, don't want the scrutiny. I looked up some of them on Wikipedia, just vendors who buy Google data in their real-time bidding system, for example. I can't find any information about them.

And you'd think, well, these are, this is one of 4,000 companies that has a business relationship with Google. Surely they're respectable enough that I'd be able to find anything on them. But this whole world of data brokerage is shrouded in mystery. Those real-time bidding networks that you mentioned in particular are extremely complex, and they're also extremely opaque to even try to explain them to the ordinary person.

You really have to delve pretty deep into, you know, well this is how an ad is served. It's in this instantaneous auction. And all of these brokers are, or bidders are sitting there and they're all trying to win, uh, an instantaneous computerized auction for your, uh, device.

And, uh, in exchange, you are passing a bunch of information back to that exchange. And all 4,000 of them can see it in theory, in most of these exchanges. They're not supposed to save information, uh, about your device, but many of them don't follow those rules.

Uh, many of them, as you say, are these tiny entities that we don't even know how to get in contact with. And I found examples of government-linked contractors, uh, having what look like shell companies which sit on these exchanges or participate in this data broker ecosystem in order to conceal the government's, uh, acquisition of this data.

So there's a giant defense contractor here in the US called Sierra Nevada. You go to their website, it's got giant futuristic planes on it and orbiting space satellites. And then there's a tiny little marketing company also in the DC area called N Context.

And if you look deep in the corporate records somewhere, or the terms of service on their website, it does say that they're a division of this giant defense contractor. But if you just load up their website, it looks like an ordinary, normal marketing firm. And they did work with the YMCA in New York and a Philadelphia concert venue.

And, uh, they were advertising their services. Well, I dug into this and what they were doing was getting large amounts of this real-time bidding data as a marketing company. And, uh, they had all these subcontracts with some very spooky looking three-letter government agencies.

And so it sure looks like a setup designed to obscure the fact that a government defense contractor is participating in this world of real-time bidding and getting devices on almost every phone on earth, right? Like anything that receives targeted mobile banner or web advertising is sharing some sort of data with these exchanges.

And it's a tremendous resource for governments. None of these companies should have been naive enough to, you know, expect that it was just going to be used for commercial purposes. They created a giant repository for cyber data, and they should not act shocked that lots of governments have plugged themselves into it.

And yet some do act shocked. You talked about one company that kind of had their head in the sand about who was actually buying their data until someone kind of did a bit of a sneaky ruse and made them aware of it to the fact where they couldn't deny it. Tell me that story.

Yeah, so there was a data broker in the United States; at the time it was called Uber Media, it's now called Near, uh, and actually I think it just went bankrupt and changed his name again. 'Cause this is how this stuff works. As you say, it's turtles all the way down. But at the time, uh, they were based in California, and you know, this government contractor approaches them and he says, Hey, uh, I've got a humanitarian client that needs data on Syria.

And, uh, you know, they're sure here you go. And you know, I talked to some employees who were involved in this deal at the time, and a lot of them said, yeah, this didn't really pass the smell test. We had a lot of suspicions, but at the end of the day, the contract said what it said, and, and they licensed the data and they paid their bills.

And so what are we to do about it? And yeah, it took another government contractor, um, mostly out of what seemed to be revenge. But, you know, I, I don't know the exact motivation, but basically a competitor, right? Yeah. It was the competitor. He tipped them off that, uh, oh, you know, that that company you're doing business with, that it's actually a government entity and it's, you know, it's the military that's getting your data.

And that, you know, that's a story that repeated a number of times, uh, both in my reporting and in the reporting of other reporters. Joseph Cox at 404 Media just uncovered that there is an Israeli company that has the exact same setup as Sierra Nevada. They have a, a defense and intelligence arm, and then they have a marketing company front, and they seem to be getting data through one and passing it to the other and then passing it to government clients.

And so this is something that happens all over the world and with all sorts of governments. And a lot of these brokers don't really bother to do any real due diligence on who they're selling to. And even when they are alerted that their client is a, a government or a military entity, they find it hard to break off that relationship.

'Cause they need the business. And to them, uh, the government's just another customer. We've collected the data legally, they're buying it legally. The bills paid, what's the problem? And they're getting a lot of money, Right? This broker, Uber Media, you know, that was a couple hundred thousand dollars a month for the government. That's cheap.

That's a couple minutes of running a fighter jet. Mm-Hmm, . Uh, but for the, these companies that can be, you know, a pretty substantial, especially when they're startups, especially when they're young companies, that can be a pretty substantial piece of their, their monthly revenue numbers. And so for them, it's hard to say no even when they find out the truth behind, uh, what's really happening.

What did Uber Media do when they found out that this humanitarian organization was actually a government, uh, contractor? Oh, they kept selling data and they kept selling data right up until the moment where I called all four of the ad exchanges that were providing them the data and told them exactly what was happening and that I was going to put this in a story in the Wall Street Journal, and then they were cut off.

So it really, you know, it takes a lot, uh, to, to get, to stem this pipeline. And I'm sure the government in the last few months has figured out a completely different way to get the exact same data through a, a different shell company or a different vendor.

I want to dive specifically into one of these methods of data collection. It's the newest phenomenon that you talk about in your book, which is the idea that we're downloading hundreds of apps on our devices. We are giving away countless permissions. They're very invasive into our lives, and we have no idea what SDKs were snuck into the code.

And a lot of the time you have app companies that aren't making any money, someone comes along and says, “Hey, we'll pay you a few thousand dollars a month to stick this piece of code in your app. It's just for analytics purposes”. The app developer is really happy because they get paid, but meanwhile, we've now added spyware into all the apps that we're using.

And that's just being siphoned straight back to governments, hostile entities, you name it. Anyone could be putting this code into the app. So just walk me through this phenomenon of unknown SDKs in apps. Yeah, so it's actually pretty common in the app development world to borrow software libraries from something like GitHub.

Uh, in, in other instances, you can go and, and find these companies that are willing to pay you to put a little bit of software in your app in exchange, uh, that software pulls data from your users. You get a little bit of money, everybody wins except the consumer, right? Because unless you know how to decompile apps, and I don't even think it's possible on an iPhone because it's such a closed ecosystem, but unless you know what you're doing and you're highly technically skilled and know how to route the device and see what it's doing, the consumer really has no idea what code is running in these apps.

We just have to trust that Apple and Google have looked, uh, at the software and found nothing malicious. And I, I don't trust those representations because time and time again, we've seen that these developers put these very strange lines of code in there.

And perhaps there is a mention in the privacy policy somewhere that some sort of data's being collected by third parties. Sometimes there isn't. Sometimes it's above board contractors, uh, collecting location data with quasi the permission of the user. Sometimes it's straight up malware where the, the software that's being put in these apps is behaving in ways that the user wouldn't expect or even the app developer wouldn't expect.

And I found in doing this research, there was one such effort that appeared to be targeted at apps in the Middle East. Some of them were Muslim-themed prayer apps or other sort of Muslim or Middle Eastern themed apps that had large user bases in that region. Others were targeted at Eastern Europe or, uh, Southeast Asia or East Asia.

The through line is that the developers did not seem to know what they had put in the device, and that the code seemed to be able to do some highly unusual things like scan the entire, uh, wifi network for other devices on the wifi network. Well, that's a pretty powerful intelligence tool. If you're gonna do a, a hack or you're gonna break into someone's device with a more intrusive attack, you might wanna do a little bit of reconnaissance first to see what other devices are on the network.

What, what kind of router are they using? What kind of smart TV are they using? What kind of vulnerabilities can we introduce into this network? In some instances, the code seemed to have the ability to look at the WhatsApp download folder, and that's something governments are extremely interested in, right? Because WhatsApp is in theory, end-to-end encrypted the, of the messages between users can't be detected.

But if you can scan the WhatsApp downloads folder, you might be able to understand what kind of files these users are trading amongst each other. Is it pornography? Is it, uh, terrorist propaganda or is it, is it funny memes, right? So you might be able to tell something about these people.

And when I talked to some of these app developers, they seem to have no idea. And honestly, a lot of them didn't seem to care that much, right? I mean, they, they said, well, you know, they offered me money, I put it in there, I'll take it out if Google says I have to take it out. And that's, that's the app ecosystem to be honest.

And Google themselves is paying app developers to put their code into apps so that they can collect data as well. I mean, they're, they're all doing it, Right? The difference though is that these large tech companies, which by and large are not the focus of my book, they actually genuinely do have to care about what the user thinks, right?

If there's some sort of violation of trust on the part of Google, they might actually lose billions in revenue if lots of users stop trusting them. So they do have to balance their data collection against what they think the user is going to tolerate.

And these, uh, software development kit makers have zero relationship with the public, right? They don't have to care what the public thinks about them. And, and a lot of these cases, these app developers are giving away the app for free. And, uh, you know, they don't carry all that much either, and they're kind of at the margins of the tech economy.

These data brokers have very little consumer relationship. Uh, they're largely business to business. And so in a market like that where you have data collection against the population, but no accountability towards the population and no ability for consumers to really voice frustration and, and, and change services, then you get the world I'm describing where, uh, these companies put these software libraries in all sorts of apps and do it somewhat surreptitiously.

Yeah. And it's so difficult. I don't think people quite-- can even fathom how large these code bases are, how difficult it is to figure out what any of the code is. I know that some malicious software was just, uh, snuck into a, a Linux distro, and in order to get rid of that, they said that they might have to roll back the distribution tour released from two years ago before this malicious person had made any commits to the open source repositories.

So it just gives you an idea of how complicated all these things are. Like if someone wants to sneak in code that tracks every single thing you're doing, you're probably not gonna find it. Right? And you, you know, it took two computer scientists to unwind that little, what appeared to be an intelligence collection effort.

They have PhDs and academic appointments, you know, the ordinary person does not have those kind of resources. And I'm sure there are other apps with similar software that nobody has identified yet, because all of these things are very difficult to detect, even in open source software where the code is in theory, uh, you know, it is auditable by anybody.

And in theory there are lots of eyes on it. We've seen time and time again that there's vulnerabilities in that kind of software. So who the heck knows what is being run on code that we can't see, that we don't have access to that is somewhat of a black box.

And, and that is a huge challenge for all of us, that our devices do things that we just can't know about unless we are computer scientists with PhDs. And, uh, that poses real threats to, you know, the privacy and the security and even the dignity of, of billions of people around the world that have increasingly, uh, used these systems for everything in their lives.

One thing that I wanted to just touch upon that I thought was a really important insight you brought up in the book is this distinction between law enforcement and intelligence. Because at the intelligence level, at the NSA level, we have these incredibly powerful machines that are sifting through all of this data and collecting data about all of us.

And the, the way that they couch it is, oh, we're not looking at Americans. We're really looking overseas. But then suddenly you have local law enforcement agencies within the United States getting access to these same tools who are not using it judiciously who are using it to target certain people.

There's a big difference between law enforcement using these tools and intelligence using these tools that you kind of dived into in your book. Talk to me about that. 'Cause I think a lot of people see government as this monolithic entity. It's just a single umbrella, but actually the use cases and, and uses of this data really does vary and is important.

Yeah, I think a lot of people are very cynical about the intelligence agencies, but in to their credit, they do try, um, to the utmost of their ability not to target Americans for collection. By and large, their missions do involve targeting foreigners, uh, and are by and large directed overseas.

Now, of course, there is some debate about how much they accidentally collect on Americans and whether they can query it. So there is some nexus between, um, what the intelligence community collects overseas and, and, and the United States. And those are real policy debates.

But by and large, there's a lot of paperwork involved in a lot of this, and it's well supervised. When you're talking about domestic law enforcement, their mission is squarely aimed at the US population, and that mission is generally speaking, public safety and law enforcement.

So it involves talking about people's liberty, talking about putting them in jail, talking about subjecting them to criminal trial and criminal process. So that's a whole different level of privacy violation. And in many of these instances, you have vendors that develop tools for the military or the intelligence community, but at the end of the day, they have a sales budget and they eventually start selling the exact same tool that was originally developed for the special forces or for the intelligence community to your state police and then eventually your local police.

And so, you know, by the time I, I was reporting on this book that Pentagon project that I described at the beginning, that same data was now in the hands of the local police in many cities and communities around the country.

Yeah. And once the consequence of this, like why is that dangerous? Because there are different standards, uh, for the use of this information, but just kind of, uh, paint the picture for people who don't quite understand the distinction.

The problem is that there are, you know, more than 10,000 if not far more than 10,000, uh, law enforcement entities across the United States. And all of those vary widely in their professionalism and their training and their oversight and how closely they're supervised by lawyers or their local political establishment.

Some of them are very well run and some of them are very autonomous. And when you're talking about this kind of data, when you're talking about data that's available for sale, or it's just open source data that you can just look at by, you know, going to twitter.com/username, by and large, the courts have not put any restrictions whatsoever on police officers using that kind of data until the Supreme Court changes its jurisprudence until there's a new understanding of the Fourth Amendment.

By and large, if you are purchasing data, the police can just use it. That's not necessarily true of the intelligence community, that even if they're purchasing data, often they have to comply with very, uh, complicated laws and executive orders around the handling of American's personal data.

So they may be able to buy it on the US population, but to query it is a whole different question. And they need to go through all these steps. It needs to be approved. So there actually are a fair number of controls on what the military and the intelligence community does with this data, and far less control on what the local police do.

And, you know, the courts, regulators and, uh, lawmakers have not caught onto this, have not caught up to the reality that so much data is available for sale and that local police officers can use it for whatever they like without much oversight or with very few rules around that usage.

I think this is a really important conversation to have, and you're one of the few people I think that's mentioning it because a lot of the conversation around data collection does just center on the intelligence community. It just talks about what they're doing.

And so all of the pushback you hear is, well, you know, we've got Pfizer and we've got all of these courts that, and all this oversight and all this stuff going on. And that's not the debate we should be having because as you said, like, let, let's push that aside, then it's all these other entities that are getting access to this data, and we are not having that conversation.

We are not talking about the fact that there is almost no oversight in how this information is used, uh, whether it's used to unfairly target people or harass them or, you know, the, the corruption that goes on in some of these agencies. As you said, there's a whole spectrum of how well behaved some of these law enforcement, uh, entities are.

Some are great, some of them are really terrible and corrupt, and that's a really dangerous situation where they're getting hands on all of our most personal intimate data that we're generating on all of our devices. Yes.

And just also to expand on this, beyond just the agencies with police powers or intelligence agencies or the military, there's a whole other cadre of government entities that some people might actually say are good uses, right? There's, um, transportation departments get this kind of mobility data to do traffic planning and public health agencies who are using mobility data to do contact tracing.

So those entities that we consider much more benign also get this data. But again, we don't know what kind of controls the public health agency has on mobility data, right? Are they allowed to look up their Tinder dates? Are they allowed to look up where their spouse goes if they have large mobility data sets, right?

So there are these privacy issues and governance issues around data that are remarkably unresolved, um, across government entities of all sizes. You know, you use intelligence or military tools to look up your spouse or your neighbor or your date. You're in a lot of trouble if you do that in the transportation department. I have no idea what happens. I, I don't know.

So there's all these questions about access to this data, which is remarkably sensitive in some instances, even if it's commercially available. And so I don't think we as a society have even begun to have the right conversations about what is the actual sensitivity of some of this stuff and who should have access to it, and what are the consequences if you break those rules.

And another thing you brought up, which I think is important for people to formalize in their mind is that when we talk about government, we say government and don't realize that, that it consists of individuals within the government and also individual agencies.

And the same thing applies with companies. We talk about a company gets your data, but a company is just made up of people. And you gave a great anecdote in the book about someone who was this app developer who started, you know, collecting all of this information from an app you developed and suddenly realized like, well, you, you know, you tell the story.

'Cause I, it's a bit of a shock when you put it in these personal terms, Right? So he was a very early pioneer. He got a very popular location-based app at some point, and a lot of people were using it. And he is, you know, has all this data. He never sold it, but he, he, he's sitting on a lot of location data generated from people's phones as they move around the world.

And he's sitting there saying, I could see where my neighbor goes, you know, I can see where my spouse goes. This is, this is kind of nuts. And he never went down the path of selling it. But that's an actual human being on the other end of that computer system that has access to some data about people that could be quite sensitive, right?

He could figure out if his neighbor is, is, you know, being treated for, uh, depression. He could figure out if his neighbor had an abortion, he could figure out if his neighbor's cheating on his spouse based off of this data. And that is a remarkable peak into somebody's life.

And, and this is one of the issues with corporations collecting data, right? Because now increasingly we've seen spy agencies try to place people inside companies that, that can give them access to the content without needing a subpoena, without needing a warrant.

All you need is an engineer at Twitter or Google or Facebook that will read you out someone's messages. And there was a very famous case where the Saudi Arabian government had tried to infiltrate Twitter and so that they can monitor the DMs of activists who were critical of the government and that employee got caught and, and prosecuted.

But this happens beyond just those, that company there, there are probably, you know, hundreds of, of people on the payroll of intelligence agencies or even criminal gangs, you know? Mm-Hmm. . This is what happens when we give large tech companies access to this kind of data, is that we are exposing ourselves to individuals inside of those companies with nefarious aims.

Yeah. There's some great Darknet Diaries episodes about places like North Korea sending off people to get jobs at different companies so that they can get access to all of this personal information. It's a, it's a real problem that I don't think many people think about, Right?

And it's, it's not something that we as a society are even remotely capable of addressing, right? Because ever we're ever hungrier for more and more data, companies are not moving in the direction of collecting less. They're not moving in the direction of encrypting more or, or, you know, moving things to end-to-end encrypted services maybe in some cases.

I think Facebook has done so recently and Apple's always been in this space, but generally speaking, there's a hunger for this data. And I am not optimistic that we are going to move in a more privacy protective direction.

And so that just increases the chances that, you know, Google, Facebook, TikTok, Snapchat, these are all ripe targets for criminals and spy agencies to put people in the right job and to collect backdoor information off of them without really, you know, much ability for the public to understand that or see it.

I recently read a couple of books by Michael Hayden, and this is a former head of CIA, former head of NSA. The title Playing to the Edge is very much about like, here is how we pushed what we were doing right up to the legal edge.

I feel like that's a conversation we often have, and it's not the right conversation a lot of the time. You hear politicians and intelligence community people talking about how, well this is how we can justify it, and this is how it's within the confines of how we interpreted the law.

The conversation we should actually be having is whether or not this is good for society, whether this is something that we actually want, not whether you can do semantic backflips and justify it as legal if you have to. So talk to me about that kind of like lack of discussion about whether this pervasive surveillance is good for society.

Yeah, I think that's exactly right, that by and large we are not having this conversation as a society because intelligence agencies, the military, all of these sort of top-tier government agencies that have very important national security and public safety missions don't want to talk about it because they're worried that adversaries will change their behavior, they'll catch on to things.

And I don't, you know, as a journalist, in many ways, this is what motivated me to write the book because I did not believe that it was right in a democracy where we're supposed to, you know, understand what A, what our government is doing. And, and as a capitalistic society where B we're supposed to understand what our technology is doing, I didn't feel it was right for the public to be this in the dark about how data was being used and how technology was being used.

And so in a lot of ways, the public conversation around this really is being, uh, subordinated to the needs of these intelligence agencies and these military units rather than, um, you know, being discussed openly in civil society. And, and, and by activists and by journalists and by critics and by supporters, we're not having a public conversation about it because, you know, these intelligence agencies and these often these top-tier special forces units want these capabilities to stay quiet and useful as long as possible.

And so they do not find it in their interest to discuss it with people like me until well after it's a useful capability. And by that time, they've moved on to the next thing that I'll figure out in five or six years, and they'll have moved on to the next thing by then. It's a real issue.

You know, it's one that I think does undermine trust in government. Uh, when there is so much secrecy, it breeds a lot of cynicism among the population about what their government is doing and what their technology is doing. And I don't think it leads to healthy societies or healthy discourse around either our, uh, public safety and intelligence programs or around our technologies.

You really drilled this home in your book where you talk about how these programs only work when people are left in the dark, and it's a scary situation when you talk to people about this and they have no idea how their tech works. What's going on?

I think, I mean, what, what do you think the antidote is to all of this, just better education about this? I think there could be a role to play for legislation. Uh, you know, Congress has historically in the past been perfectly capable of, of passing laws that protect certain categories and classes of data.

Um, so you know, initially things like emails were not maybe under the fourth Amendment, but Congress went out and they passed a law. They said, okay, we're gonna bring stored communications and electronic communications under the banner of, of Fourth Amendment protections.

We're going to go out there and protect telephone conversations even though they're traveling over a public wire. So Congress can certainly enact new statutory protections for data that's collected by, uh, companies. And finally, I do think part of this world is driven by consumer reluctance to pay for things, and that we could have a healthier technology ecosystem if people were more willing to provide money in exchange for digital services or digital software.

By and large people, uh, do not like to pay for things. And, and developers understand that. They understand that, um, charging 9- even 99 cents for an app, uh, significantly limits the number of downloads you get if it's free. Well, it's not free at the end of the day, you know, uh, maybe some web services can be run by volunteers.

You know, Wikipedia is a good example. There are some good open source repositories and some code bases, but by and large, modern consumer technology is complex enough. It requires so much bandwidth. It requires real developers. It requires storage space. It requires lawyers to drop terms of service. It requires HR, payroll people.

None of this is free. When software developers can't count on money from the public, that's when they turn to doing, uh, sneaky things like putting software in or monetizing their users. And we might have a healthier technology ecosystem if people were more willing to pay, if they were willing to return to the basic exchange of capitalism, which is that I give you money and you give me a service.

And oftentimes, we're not talking about a lot of money here. I mean, we're talking about a few dollars less than a cup of black coffee to buy an app that if it gives you value, why not support a business model that at least you know, it still might sell your data. I can't guarantee you that every paid app won't do that, but you are moving us as a world towards a, towards a, a future and where technology companies can get paid for their software and for their efforts, and don't need to rely on data brokers and software libraries, uh, from shady SDK companies to make money.

And I think there's a different asymmetry that is important to recognize that data brokerage companies-- how much are they making, like on each of us, on me? How much is my data worth? I don't know, like a few dollars. But in aggregate it's huge. The problem is that the cost to me in that information being out there is huge into how vulnerable it makes the individual into how dangerous it can be to put sensitive information out there if someone wants to target you.

So there's a huge asymmetry, and it just reflects the disregard that these companies have for individual safety in that they're willing to make people more vulnerable by aggregating all of this data and selling it and having no accountability for how that data is used.

And all they're really getting is a few dollars per, per person's data. I think it's a huge issue. And on the flip side, you make a great point that if we just pay that few dollars ourselves, we gain a whole bunch of security and safety in our lives that I don't think a lot of people even realize.

Yeah, I think that's right. And it, it also, you know, there's some people that believe that the way out of this is, oh, well, um, tech companies should just pay users a little bit of money for their data, and then everyone will be happy. As you say, it's not worth that much to the user. It's only worth in money in the aggregate.

But the, the, the consequences, if somebody decides that you are of interest, whether that's a criminal or a government agency, the costs to you are potentially quite significant. As you say. It's a, it's an asymmetry that, that you know, you and, and you can't know at the time where you're being paid for your data or whatever.

These proposals are what the potential downsides are. And you can't meaningfully consent to those things because you don't know how your data could be used by an adversary that you don't, you know, you, you haven't even conceived of yet.

You brought up this idea about-- let's compare China and America, right? Let's compare the surveillance that's going on because the actual techniques are kind of similar, the amount of surveillance that's going on, very similar, but the difference is that China wants you to know that you're being surveilled.

And then the US they want it to be a secret. So I thought that was a really good distinction, uh, between these two societies. I don't wanna say that we are reaching China levels. I think the amount of data collected on all of us in the US or China is probably very similar on some levels.

However, the thing that separates us is the fact that the United States has not taken the step of weaving all this together and pushing it down to your local police officer that by and large what's collected on Americans is in a wide array of corporate and government databases.

And those things have not yet been tied together. In addition, you know, we are still a country of laws and of norms, and of one that is skeptical of government power and government authority. And I think both the government and the citizens are a little bit uncomfortable with the way things are going in the direction we're, we're trending.

But you know, by and large, the, the trends are towards more data collection and more government access to information that all of us generate. And the difference is that, that China uses data and, and as, as a form of power. And in the United States, that is seen as distasteful.

And so a lot of this takes place in the shadows, um, because they don't want the public scrutiny, they don't want the public backlash because we are still consumers and voters that can put an end to some of this.

And putting an end to it would mean the end of a capability that certain agencies inside the government find useful. So talk to me about what the solution is, because I don't want people coming away from this being like, this is crazy. It's all the shadows. There's nothing I can do.

My takeaway was be more judicious about what you install, be more critical about the technology that you're using, and seek a higher level of understanding about what that technology is doing before you dive straight in. But what would your advice be?

I think at the most basic, you should be very careful, especially about your permissions. Things do not need as much access as they want. A lot of these apps want access to your entire photo roll or your contact list or your location 24/7. And they will work just fine without it.

I would also, by and large stick to, you know, software made in rule of law democracies. If you're an American inside the United States, you have the most constitutional protections as an American. Uh, if you're outside the United States and you're using American software, well, uh, I'm sorry I have bad news for you, but you, you may be surveilled.

Generally speaking, you know, uh, using software from reputable companies. Uh, I'm a big believer in encryption. There are plenty of great encrypted services for communications. Apple's iMessage, Signal. On the email side, there's TutaNota, and then there's Protonmail. On the drive side. There's like P-Cloud and Tresorit and a bunch of things.

There's all sorts of tools out there that you can actually use to get a little bit more privacy and security. And then finally, you know, as I said, the best advice is to, to pay money because that restores the balance of power to you as a consumer. You are in charge, you are deciding to spend money on something, and that service is providing you something in return.

And if you cease to find value in it or you find their practices odious, you can stop. And that gives you and the population a lot more market power than if you are relying on advertising to support your favorite game or your favorite weather app.

And so I do think that would lead to a healthier internet if more people have that attitude. I completely agree. Well, this has been a fantastic discussion. I highly recommend that everyone go and immediately read your book because I think that it illuminates things that no one is really aware of.

And one thing I'll, I'll just mention before we sign off, you went through a, a lawsuit against the government in order to uncover some of this information. This was a deep dive into a shadowy world that no one really wanted to, um, let you into.

Yeah. I sued under the US Freedom of Information Act. I sued a bunch of government agencies and got some stuff back. But honestly three years later, that lawsuit is still ongoing. A lot of what they gave me is redacted. I had to figure it out in other ways.

And this is what I mean that a, a public conversation about a lot of this stuff, even though it's unclassified, even though this is just data that the government is buying, a lot of that gets secondary to the government's, uh, desires to keep these capabilities secret and to avoid the public scrutiny and accountability that comes along with using these tools.

And so even that lawsuit supervised by a federal judge was not tremendously effective in, in getting answers. Well, I really appreciate the lengths you went to, to uncover information so that people can start to learn about this, because you're absolutely right.

The only way that we're gonna change things is for us to start illuminating the shadows, to start unveiling all of this stuff that is going on behind closed doors and having a public discussion about it so we can decide what we want as a society and what we want as individual consumers.

So thank you so much and uh, I hope that everyone goes and reads your book. Thank you so much for having me.