25 years of mass surveillance is enough

25 years of mass surveillance is enough

大规模监控二十五年,已经够了

25 Years of Mass Surveillance Is Enough. This essay was written with Cindy Cohn, and originally appeared in Lawfare. One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata.

大规模监控二十五年,已经够了。本文由我与辛迪·科恩(Cindy Cohn)共同撰写,最初发表于《法律战》(Lawfare)杂志。9/11 恐怖袭击留下的众多遗产之一,是政府层面从“针对性监控”(如个人窃听或电话记录追踪令)向“大规模监控技术”(如接入互联网骨干网或大规模收集电话/互联网元数据)的全面转变。

The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in immigration actions and against people exercising their First Amendment rights to protest. It’s also increasingly part of private security systems, such as facial recognition at venues such as Madison Square Garden and networked Flock license plate capture systems on roads and in parking lots.

现代大规模监控的法律与技术架构最初被包装为抵御恐怖威胁的必要手段,但如今其应用范围已远远超出了这一初衷及国家安全的范畴。大规模监控现已成为执法部门的常规工具。美国移民及海关执法局(ICE)将其用于移民执法,并针对行使第一修正案抗议权利的民众。它也日益成为私人安保系统的一部分,例如麦迪逊广场花园等场所的人脸识别,以及道路和停车场中联网的 Flock 车牌捕捉系统。

The interrelation between private and governmental mass surveillance is worth examining. Surveillance is the business model of the internet; companies like Google and Facebook constantly spy on their users’ behavior. From the National Security Agency relying on data collected by telecommunication and internet companies, to local sheriffs and ICE agents relying on cellphone location data and privately managed automatic license plate readers, governments primarily obtain the mass surveillance information through private companies.

私人监控与政府监控之间的相互关联值得深究。监控是互联网的商业模式;谷歌和脸书等公司不断窥探用户的行为。从国家安全局(NSA)依赖电信和互联网公司收集的数据,到地方治安官和 ICE 特工依赖手机定位数据及私人管理的自动车牌识别器,政府获取大规模监控信息的主要渠道正是这些私营企业。

Increasingly, access doesn’t just come through legal processes, either. FBI Director Kash Patel recently confirmed in congressional testimony that the agency is purchasing information on Americans from data brokers and intends to continue to do so. This pipeline from private collection to governmental collection means that as companies collect more information for surveillance capitalism purposes, more is available to law enforcement as well. And as the technology for mass surveillance and analysis improves, especially with the increased use of AI technologies, the problems attendant to mass surveillance grow as well.

此外,获取信息的途径也日益脱离法律程序。联邦调查局(FBI)局长卡什·帕特尔(Kash Patel)最近在国会证词中证实,该机构正在从数据经纪人处购买美国人的信息,并打算继续这样做。这种从私人收集到政府收集的渠道意味着,随着企业为“监控资本主义”目的收集更多信息,执法部门可获取的数据也随之增加。随着大规模监控和分析技术的进步,特别是人工智能技术的广泛应用,大规模监控所带来的问题也愈发严重。

After 9/11, the idea that the government could surveil the population to safety took hold. In 2001, the fear of terrorism reached a frequency and intensity never before seen. Along with that came the fear that the enemy could be anyone, anywhere. As a result, the government’s response was to watch everyone, everywhere. This line of reasoning underpinned the shift from targeted to mass surveillance.

9/11 事件后,“政府可以通过监控民众来确保安全”这一观念占据了主导地位。2001 年,对恐怖主义的恐惧达到了前所未有的频率和强度。随之而来的是一种恐惧:敌人可能是任何人,出现在任何地方。因此,政府的应对措施就是监控所有人,监控每一个角落。这种逻辑支撑了从针对性监控向大规模监控的转变。

Or, in the words of an internal National Security Agency (NSA) presentation that was made public as part of Edward Snowden’s 2013 disclosures, a government that can “Collect it All,” “Process it All,” “Exploit it All,” “Partner it All,” and “Sniff it All,” will ultimately, “Know it All.” Similar rationales support the rise of domestic mass surveillance: if law enforcement could see and hear everything, it could more effectively interdict and solve serious crimes.

或者,用爱德华·斯诺登 2013 年披露的一份国家安全局(NSA)内部演示文稿中的话来说,一个能够“全收集”、“全处理”、“全利用”、“全合作”和“全嗅探”的政府,最终将实现“全知”。类似的理由也支持了国内大规模监控的兴起:如果执法部门能看到并听到一切,就能更有效地拦截和侦破重大犯罪。

The national security community has never provided a full analysis of the costs and benefits of these mass surveillance programs, either in terms of taxpayer dollars or diversion of resources from other efforts—or any demonstration that those techniques stopped attacks that otherwise they would not have been able to prevent. While the NSA occasionally presents examples of the successes due to its mass surveillance programs, especially when those techniques are under public pressure, the examples also regularly fall apart upon serious scrutiny.

国家安全部门从未对这些大规模监控项目的成本和收益进行过全面分析,无论是纳税人的金钱投入,还是从其他领域挪用的资源——也没有任何证据表明这些技术阻止了原本无法预防的袭击。虽然 NSA 在面临公众压力时偶尔会展示其大规模监控项目的成功案例,但这些案例在严谨的审查下往往经不起推敲。

And even if some utility exists, it must be seriously weighed against the costs. Similarly, there has never been any comprehensive analysis about whether domestic immigration or law enforcement’s use of these techniques actually makes people safer, or whether other techniques could produce the same results. Instead, both the police and the companies selling these tools float anecdotes and dubious data. For example, Flock’s data equates the number of law enforcement hits in their database with actually solving crimes.

即便这些技术确实存在某种效用,也必须将其与成本进行认真权衡。同样,从未有过全面的分析来证明国内移民或执法部门使用这些技术是否真的让人们更安全,或者是否有其他技术能达到同样的效果。相反,警方和销售这些工具的公司只会抛出一些轶事和可疑的数据。例如,Flock 的数据将数据库中执法部门的“命中次数”等同于“实际侦破的案件数量”。

Twenty-five years after 9/11, it seems reasonable to step back and evaluate the costs of this shift to mass surveillance, especially in terms of Americans’ rights and freedoms.

在 9/11 事件过去二十五年后,退后一步,评估这种向大规模监控转变所带来的代价,特别是对美国人权利和自由的影响,似乎是合情合理的。

The Shift: The easiest place to see a shift to mass surveillance was in the government’s decision immediately after 9/11 to collect Americans’ telephone records. The program started under an argument of pure executive power as the “President’s Surveillance Program.” But in 2006, that argument secretly shifted to a novel interpretation of Section 215 of the Patriot Act which had only previously authorized more targeted access to records.

转变:最容易观察到大规模监控转变的地方,是 9/11 事件后政府立即决定收集美国人的电话记录。该项目最初以“总统监控项目”的名义,基于纯粹的行政权力论点启动。但在 2006 年,这一论点秘密转向了对《爱国者法案》第 215 条的一种新颖解释,而该条款此前仅授权进行更具针对性的记录访问。

While some media and public interest organizations struggled to force the government to reveal the program as early as late 2005, the government only officially confirmed it after the 2013 Snowden disclosures. In 2015, the Second Circuit Court of Appeals rejected the government’s interpretation of Section 215 as allowing mass collection of telephone records. Later the same year, Congress passed the USA Freedom Act. While this new law still allows collection of a tremendous amount of domestic telephone records, it ended the indiscriminate mass collection that had occurred for nearly fourteen years.

尽管一些媒体和公共利益组织早在 2005 年底就努力迫使政府披露该项目,但政府直到 2013 年斯诺登披露后才正式确认。2015 年,第二巡回上诉法院驳回了政府关于第 215 条允许大规模收集电话记录的解释。同年晚些时候,国会通过了《美国自由法案》。虽然这部新法律仍然允许收集大量的国内电话记录,但它终结了持续近十四年的无差别大规模收集行为。

Other shifts to mass surveillance continue through today. The NSA launched its Upstream program, which involved intercepting both metadata and content from key telecommunications junctures inside the U.S., soon after 9/11. It was also initially conducted under a claim of purely presidential authority. This program was brought under marginal congressional and programmatic (not targeted) Foreign Intelligence Surveillance Act (FISA) court review via Section 702 of the 2008 FISA Amendments Act. In 2017, more than 15 years after its inception, the NSA ended content searches due to FISA court pressure, but the mass collection continues.

其他向大规模监控的转变一直持续至今。9/11 事件后不久,NSA 推出了“上游”(Upstream)项目,涉及从美国境内的关键电信节点拦截元数据和内容。该项目最初也是在纯粹的总统权力主张下进行的。通过 2008 年《外国情报监视法》(FISA)修正案第 702 条,该项目被纳入了边缘性的国会审查和程序性(而非针对性)的 FISA 法院审查。2017 年,在项目启动 15 年多后,NSA 因 FISA 法院的压力停止了内容搜索,但大规模收集仍在继续。