• China vs. U.S.: Privacy for Whom?

    September 13, 2022 // 3 Comments »

    The New York Times ran an article on the use of surveillance tech in China. One wishes they would do the same for the U.S.

    The NYT article came to some scary conclusions about autocratic China. Chinese authorities implement facial recognition tech everywhere they can, the police seek to connect electronic activity (making a call) to physical location, biometric information such as fingerprint and DNA is collected on a mass scale, and the government wants to tie together all of this data to build comprehensive profiles on troublesome citizens. The latter is the Holy Grail of surveillance, a single source to know all there is known about a person.

    Should the Times (or China) wish to expand its review of invasive government surveillance technology, particularly those technologies which integrate multiple systems, it need look no further than its hometown police force, the NYPD, and data aggregated into the little-known Consular Consolidated Database (CCD) by the U.S. State Department.

    Prior to 2021, when the New York City Council passed the Public Oversight of Surveillance Technology (POST) Act, citizens were left to piece together the various technologies used to surveil them based on scattered media reports. We know now the NYPD deploys facial recognition surveillance (and can retroactively employ facial recognition against video saved from one of 20,000 cameras), x-ray vansStingraysShotSpotters, and drones, among others, equipment all originally deployed in the Iraq and Afghan wars. But we still don’t know how many of these technologies are used in coordination with each other, and, as in China, that is the key to understanding their real effectiveness.

    POST reporting and other sources offer some clues. The NYPD uses the smartphone-based Domain Awareness System (DAS), “one of the world’s largest networks of cameras, license plate readers, and radiological censors,” all created by Microsoft with video analytics by IBM. DAS also utilizes auto­mated license plate read­er (ALPRs) devices attached to police cars or fixed on poles to capture the license plates of all cars passing by. ALPRs can also capture photo­graphs of cars, along with photos of the driver and passen­gers. This inform­a­tion is uploaded to a data­base where it can be analyzed to study move­ments, asso­ci­ations, and rela­tion­ships. Facial Iden­ti­fic­a­tion can then run photos, includ­ing from data­bases of arrest photos, juven­ile arrest photos of chil­dren as young as 11, and photos connec­ted to handgun permits. The system analyzes an image against those data­bases and gener­ates poten­tial matches in real-time.

    Included in DAS is a translator application which helps officers communicate with community members who do not speak English, while of course also recording and storing their remarks. DAS ties in to ShotSpotter, a technology developed for the Iraq War which pinpoints the sound of gunfire with real-time locations, even when no one calls 911. This technology triangulates where a shooting occurred and alerts police officers to the scene, letting them know relevant information, including the number of shots fired, if the shooter was moving at the time of the incident (e.g., in a vehicle), and the direction of the shooter’s movement. DNA data can also be accessed, so wide-spread collection is a must. One area of activity outlined in Chief of Detect­ives Memo #17 instruc­ts on how to collect “aban­doned” DNA samples from objects such as water bottles, gum, and apple cores. For example, police officers are taught to wait for the suspect to take a drink or smoke, and collect the sample once a suspect throws the cup or butt away.

    What is deployed in New York to aggregate sensor and bio data (including social media monitoring and cell phone locator services, which when tied to facial recognition can identify individuals, say who attend a protest, visit an AIDs clinic, etc.) will no doubt be coming soon to your town as the weapons of war all come home. The next step would be to tie together cities into regional and then state-wide networks. The extent to which inform­a­tion obtained from DAS is shared with federal agen­cies, such as immig­ra­tion author­it­ies, remains unknown. What we do know is the phrase “reasonable expectation of privacy” needs some updating.

    Perhaps the largest known data aggregator within the Federal government is the innocent-sounding Consular Consolidated Database (CCD) administered by the U.S. Department of State. Originally a simple database created in the 1990s to track visa and passport issuances, the CCD is now one of the largest global databases of personal information, growing at a rate of some 35,000 records a day. The system collects data from both foreign visa applicants and American citizens to include but not limited to imagery for use with facial recognition, biometric data such as ten-fingerprint samples, home/business addresses, phone numbers, email addresses, financial information, race, gender, social security and alien registration numbers, passport information, certain Federal benefits, medical information, legal information, education information, family information, travel history, arrests and convictions, and social media indicators.

    The CCD is especially valuable in that it is a database of databases, pulling together information collected elsewhere including abroad, as well as from some commercial databases and public records, and making the aggregate available both for individual search by identifiers like name, social security number or facial recognition, but also for very large scale analytic searches to identify patterns and trends. This massive pool of data is then made accessible to the Department of Homeland Security, Department of Commerce, Department of Defense, Department of Justice, Office of Personnel Management, Federal Bureau of Investigation, and “other interagency partners” to include potentially intelligence services. In addition to the State Department, information is regularly input into the CCD by the FBI, the Integrated Automated Fingerprint Identification System, DEA, ICE, IRS, DOD, Treasury, Health and Human Services (HHS), DHS, Interpol, and U.S. Marshal Service (USMS.)

    Numbers of records held by CCD are not available, with the last public tallies documented in 2016 showing 290 million passport records on American citizens, 25 million records pertaining to American citizens living abroad, 184 million visa records of foreigners, and over 75 million photographs. Some 35,000 records are added to the CCD daily, so do the math given the existing tallies are up to 13 years old. As a point of comparison, Google’s database of landmark photos holds only five million records. The Library of Congress database lists 29 million books.

    The New York Times article about surveillance in China is scary, showing what a vast, interconnected system is capable of doing in exposing a person’s life to scrutiny. The Chinese authorities are, however, realistic about their technological limitations. According to one bidding document, the Ministry of Public Security, China’s top police agency, believed one of their biggest problems was data had not been centralized. That Chinese problem appears well on its way to resolution inside the United States, and that is also quite scary.

    Related Articles:




    Copyright © 2020. All rights reserved. The views expressed here are solely those of the author(s) in their private capacity.

    Posted in Democracy, NSA, Other Ideas, Post-Constitution America