Category: Signals & Safeguards

A concise weekly newsletter tracking surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

  • Signals & Safeguards — Issue 6

    Wednesday, April 22, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    Signals & Safeguards newsletter masthead

    At a glance

    • The fight over federal surveillance powers remains unresolved.
    • Commercial data, plate readers, facial recognition, and AI-assisted tracking are converging.
    • The clearest safeguards this week are still practical ones: tighter account security, faster patching, and less collection by default.

    Section 702 survives for now, but the real fight is not over

    Congress approved only a short-term extension of Section 702 through April 30 after lawmakers failed to agree on a longer renewal. The procedural fight in the House shows the core dispute is still whether broad surveillance powers continue while warrant reforms are deferred again.

    Why it matters for Bend: weak federal guardrails do not stay neatly in Washington. They shape the broader privacy environment local governments inherit.

    San Jose’s camera network is becoming a constitutional test case

    Three San Jose residents have filed a federal class action challenging the city’s use of nearly 500 license plate reader cameras, arguing that the system amounts to unconstitutional mass surveillance. The suit turns a familiar policy argument into a live legal test about retention, bulk monitoring, and whether routine driving should quietly generate searchable location history — with 10th Circuit precedent on location data providing important legal backdrop.

    Why it matters for Bend: cities should study this kind of challenge before expanding surveillance systems. If a program is hard to explain, limit, and audit, that is a warning sign.

    Shared pattern: the strongest stories on this page all point in the same direction: surveillance power is expanding not only through dramatic new tools, but through easier data access, broader search capacity, and better ways to connect scattered pieces of personal information into a fuller picture of a person’s life.

    ICE’s SAFE HAVEN contract points toward AI-assisted pattern-of-life mapping

    ICE is set to spend $12.2 million on Project SAFE HAVEN, an AI geotracking system described as using persistent passive data collection to map immigrants’ routines and locations. The next layer of surveillance capacity is not just finding a person once, but modeling how they live and move over time, as contract documentation reviewed by The Lever makes clear.

    Why it matters for Bend: policymakers should ask not only what a system collects, but what it can infer or reconstruct later when data streams are combined.

    Citizen Lab shows how ordinary app data can become a surveillance tool

    Citizen Lab’s reporting on Webloc shows how data drawn from consumer apps and digital advertising can be repurposed into a geolocation surveillance system used at enormous scale, with coverage of roughly 500 million devices. The larger lesson is that the data pipeline itself is often the story.

    Why it matters for Bend: local privacy risk does not begin only when a city buys a camera or launches a platform. It can also grow through outside data markets and vendor partnerships.

    Mobile Fortify brings field identification closer to real time

    Reporting on ICE’s Mobile Fortify system indicates officers can identify people in the field using face photos and contactless fingerprints, rather than waiting for a later database review. Paired with SAFE HAVEN, this points to a broader shift: immigration enforcement is building tools not only for searches after the fact, but for rapid field identification already deployed near protests.

    Why it matters for Bend: systems built for quick identification deserve extra scrutiny because speed leaves less room to question accuracy, challenge misuse, or limit retention.

    Opting out may not actually stop the tracking

    An independent audit reported by 404 Media found that many tested sites still placed advertising cookies after users opted out. If people say no and tracking continues anyway, the problem is enforcement, not just design.

    Why it matters for Bend: consent language means little if the underlying system does not honor it in practice. Officials should ask not just what a privacy policy promises, but how the system behaves when someone tries to refuse or limit it.

    Google promised notice. ICE got the data anyway.

    EFF documented how Google provided a user’s data to ICE without the advance notice Google had long said it would give except in narrow situations. Independent analysis of the incident finds the deeper warning is broader than one case: protections that exist mainly in company policy language can become fragile when government requests arrive and users have little ability to contest them in time.

    Why it matters for Bend: cities and counties should be cautious about trusting vendor promises that are not backed by enforceable limits or meaningful user rights.

    The most dangerous surveillance is the kind no one voted on and no one remembers authorizing.

    Signals worth tracking

    These items point toward where surveillance systems and governance fights may be heading next. Wearable surveillance is moving closer to ordinary consumer use. States and local governments are testing rules that may prove more concrete than federal policy.

    Signals section header

    Meta’s smart-glasses fight is really a fight about ambient facial recognition

    The ACLU and dozens of partner groups warn that facial recognition in smart glasses could normalize wearable, casual identification in everyday life.

    Virginia signs a law banning the sale of precise location data

    Virginia’s new location-privacy law is one of the strongest policy signals because it is not just a proposal. It is a signed law. That makes it worth watching as a concrete example of a state treating precise geolocation as too sensitive to be traded like ordinary commercial data.

    Maryland moves against surveillance pricing

    Maryland has passed legislation aimed at stopping large retailers and delivery services from using personal data to set individualized prices.

    Monroe County requires disclosure of sheriff surveillance-tech purchases

    Monroe County’s new disclosure rule is a useful local-governance signal because it focuses on something simple and replicable: if a department is buying surveillance technology, the public should at least know what it is, what it is for, who sold it, and how it is being funded.

    Europe’s age-verification app is testing the promise of privacy-preserving ID

    The EU says its age-verification app can prove age without broadly revealing identity, though security researchers have already found vulnerabilities in the system. Broad coverage of the rollout notes the real question is whether such systems stay narrow or widen into a broader identity layer — a concern backed by strong public support for age verification that creates political pressure to expand scope.

    The Parents Decide Act would push age verification down to the operating-system level

    H.R. 8250 shifts the age-verification question closer to the device itself and raises whether the operating system becomes the gatekeeper for identity and age status. The full bill text and legislative history are available from Congress.

    Republicans are preparing another national privacy-law push

    A new House GOP privacy proposal is reportedly in development, with preemption and limits on private lawsuits likely to be central fault lines again.

    Border surveillance systems keep getting bigger and more integrated

    Rest of World’s reporting on Seguritech and Torre Centinela is a useful reminder that surveillance expansion often happens through infrastructure, not just headlines: more cameras, more drones, more plate readers, and more system integration across agencies and regions. Data-sharing arrangements between Texas authorities and Mexico have already sparked alarm on both sides of the border.

    DHS is building smart glasses for real-time biometric identification on American streets

    Budget documents reveal the Department of Homeland Security is developing “ICE Glasses” — specialized smart glasses that will pulse vast federal biometric databases, including facial recognition and walking gait analysis, to identify people in real time. The project targets a 2027 delivery date and builds directly on military tracking systems developed during the global war on terror. A DHS attorney quoted in the reporting notes that the same architecture applies equally to protesters and anyone else within a field agent’s line of sight.

    Why it matters for Bend: a system described as targeting one population is built on technology that sees everyone. The infrastructure being built for immigration enforcement is the same infrastructure that would surveil anyone in range.

    Government AI is combining with the data broker loophole to bypass warrant requirements

    EPIC’s Surveillance Oversight Director documents how the government is pairing bulk data purchases from commercial brokers — location histories, browsing data, and more — with advanced AI analysis, bypassing constitutional warrant protections that would normally apply. The concern is sharpened by the concurrent push to deploy Anthropic’s Mythos AI across federal agencies and the unresolved Section 702 debate.

    Why it matters for Bend: each loophole on its own is concerning. Combined with AI analysis at scale, they form a surveillance architecture that is qualitatively different from anything that existed even five years ago.

    Google’s AI now scans your entire photo library by default

    Google’s latest Personal Intelligence update means Gemini now scans users’ full photo libraries — described as using “actual images of you and your loved ones” — to generate personalized AI content. The feature is opt-in, but the pattern it represents is not: AI systems are beginning to process the full personal archive of a person’s life, not just what they consciously choose to share.

    Why it matters for Bend: when the default assumption shifts from “my data stays mine” to “my data is available unless I actively refuse,” the privacy burden has transferred entirely to the user.

    Direction of travel

    Taken together, these signals show surveillance power moving in three directions at once: closer to the body through wearable devices and biometric identification in the field; deeper into the data supply chain through commercial ad data and personal archives repurposed by AI; and lower in the technology stack, where operating systems and device defaults are becoming the new front line for identity and age verification. Each of those shifts makes individual opt-out harder and collective accountability more necessary.

    States are beginning to test concrete responses — Virginia on location data, Maryland on surveillance pricing, Monroe County on disclosure. None of those laws will stop the broader trend. But they point toward what meaningful restraint actually looks like when it moves past a proposal stage. The gap between those local signals and the federal picture remains wide.

    Practical habits that lower risk

    These are the practical protections and governance habits that stood out most clearly this week. Good safeguards usually start with less data and clearer boundaries. Better defaults often matter more than dramatic new tools. Public trust depends on protections that are visible and enforceable.

    Safeguards section header

    Protect messaging accounts like infrastructure

    The FBI warns that Russian intelligence-linked actors are targeting commercial messaging accounts through phishing and account compromise, not by breaking encryption itself. Treat verification codes, login prompts, QR requests, and urgent support messages with suspicion until they are verified out of band.

    A PDF is not always “just a document”

    Adobe says a critical Acrobat and Reader flaw is being exploited in the wild and could lead to arbitrary code execution. Security researchers have documented active exploitation of this zero-day. Opening a document should not be treated as risk-free by default, especially on software that offices use every day.

    Partial data leaks can still power convincing scams

    Booking.com confirmed that hackers may have accessed customer data tied to reservations, including names, email addresses, phone numbers, and booking details. Even without payment-card numbers, that kind of information can make phishing attempts sound legitimate. Supply chain analysis of the breach suggests the attack vector extended beyond Booking.com directly.

    Small organizations still need boring cybersecurity basics

    NIST’s latest small-business cybersecurity draft is a useful closing reminder because it reinforces a consistent truth: good security often comes from fundamentals, not drama. Inventories, updates, limited permissions, and clear responsibility lines may not sound exciting, but they are often what keep ordinary mistakes from becoming serious incidents.

    Treat push notification settings as part of your privacy hygiene

    EFF’s latest Deeplinks guide documents how push notification content reaches government investigators more easily than most users expect. Apple and Google now require a judge’s order to share notification data, but forensic extraction tools can still recover deleted notification text directly from devices — including from secure messaging apps. The practical fix: disable message previews for sensitive apps and treat anything visible on your lock screen as potentially accessible to anyone who holds your phone.

    April’s patch window is tight — and one critical flaw was left open

    Microsoft’s April Patch Tuesday addressed 163 vulnerabilities including an actively exploited SharePoint spoofing flaw — but left BlueHammer, a publicly disclosed elevation-of-privilege zero-day in Windows Defender, without a patch until May. CISA simultaneously added 8 more vulnerabilities to its known-exploited catalog, including flaws in Cisco SD-WAN Manager and Synacor Zimbra, with a federal remediation deadline of April 23. The patching backlog is growing faster than most organizations move.

    Bottom line: the strongest safeguards this week are not flashy. They are disciplined ones: tighter account hygiene, faster patching, and less trust in default claims.

  • Signals & Safeguards Issue 5 • Wednesday, April 15, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    Signals & Safeguards newsletter masthead

    At a glance

    • Sensitive government data systems are expanding in troubling directions at the same time oversight fights are intensifying.
    • Commercial and government surveillance tools continue to blur lines that once required warrants, audits, or clearer public approval.
    • Federal officials are still pushing major surveillance authorities even as new compliance concerns come into view.

    Main stories

    Federal personnel agency seeks broad access to workers’ medical records

    The Office of Personnel Management is seeking personally identifiable medical and pharmacy claims data for millions of federal workers, retirees, and family members covered by federal health plans. Reporting says the proposal could give OPM access to highly sensitive information about prescriptions, diagnoses, and treatment patterns, and experts have raised serious legal and privacy questions about whether such disclosures are justified or even permissible. For a broader overview of the same issue, see CBS News’ reporting here.

    Why it matters: when government asks for deeper access to health information, the question is not only whether the data might be useful, but whether the access is necessary, proportionate, and secure. That concern is sharper here because OPM itself was at the center of the massive 2015 breach that exposed records tied to roughly 22 million people.

    Why it matters for Bend: local officials should treat sensitive health or benefits data as high-risk by default. The safest rule is simple: if a public agency cannot clearly explain why it needs detailed personal data, it should not collect it.

    ICE confirms use of Graphite spyware

    ICE has acknowledged using Paragon’s Graphite spyware, a tool reportedly capable of accessing communications on targeted devices, including encrypted apps. House Democrats are now demanding answers about the legal basis, safeguards, and procurement history behind its use.

    Why it matters: this is not just another surveillance-software headline. It is a reminder that strong encryption can still be bypassed when authorities gain access to the device itself. The policy question is no longer hypothetical. It is whether government agencies are using highly intrusive tools under rules the public can actually see and contest.

    Why it matters for Bend: surveillance debates should not focus only on local cameras and sensors. Device exploitation tools can be just as consequential, and officials should ask what oversight exists before trusting assurances that a tool will be used narrowly.

    California opens a fusion center audit

    California lawmakers approved an audit of several state fusion centers after privacy and civil-liberties concerns, including allegations that information sharing may have reached beyond appropriate bounds. The audit is important because fusion centers are often described in abstract terms even though they can shape how intelligence, law enforcement, and immigration-related data move across institutions.

    Why it matters: oversight is most useful where systems are complicated, multi-agency, and hard for the public to see. Fusion centers sit exactly in that category. If data-sharing systems are lawful and well-governed, audits should help show that. If they are not, audits may be one of the few ways the public finds out.

    Why it matters for Bend: information-sharing arrangements should never be treated as purely technical back-office systems. They are governance systems, and they deserve policy scrutiny before they become routine.

    Section 702 faces renewed pressure despite major compliance concerns

    The debate over Section 702 has intensified again as Congress faces a looming deadline and critics warn that serious compliance problems remain unresolved. Senator Ron Wyden says the Foreign Intelligence Surveillance Court found major compliance issues tied to Americans’ constitutional rights, while civil-liberties advocates are warning against a clean extension with no meaningful reforms.

    Why it matters: Section 702 is often defended as a foreign intelligence authority, but the recurring fight is about what happens when Americans’ communications are swept in and later queried. The core safeguards question is whether a powerful surveillance authority should continue when the public still lacks a full picture of how serious the compliance failures are.

    Why it matters for Bend: federal surveillance rules shape the broader privacy environment local governments operate inside. When higher-level safeguards weaken, local restraint matters more, not less.

    Shared pattern: this week’s strongest stories point in the same direction: more access to sensitive information, more powerful surveillance tools, and more pressure to normalize those powers before the public fully understands the costs.


    Signals

    Signals section header

    These items matter because they suggest where surveillance systems, legal theories, and accountability fights may be heading next. Some of the most important changes do not arrive as one dramatic announcement. They arrive through contracts, court fights, pilot programs, and legal carveouts that make the next expansion easier.

    Nevada quietly signs up for Fog location tracking

    AP reports that Nevada signed a contract with Fog Data Science allowing police to query location data derived from smartphone apps, with more than 250 queries a month permitted under the arrangement. The tool can reportedly reveal “patterns of life,” including where people sleep, work, travel, and associate.

    Why it matters: this is the commercial-data loophole in practical form. The issue is not just whether police can track location. It is whether they can buy access to location data in ways that sidestep the warrant rules people assume still apply.

    Webloc shows how ad-tech data becomes mass surveillance

    Citizen Lab says a system called Webloc uses advertising-derived location data to monitor hundreds of millions of people and that customers include U.S. government and law-enforcement entities. The report suggests that app and ad ecosystems are continuing to feed a surveillance market far more powerful than many users realize.

    Why it matters: the deeper lesson is that surveillance power does not require a visible camera on every corner if commercial data markets already map movement at scale. That makes procurement, data brokers, and app ecosystems part of the same policy conversation.

    Data can be copied faster
    than rights can be restored.

    Deleted Signal messages were still recoverable through iPhone notifications

    404 Media reported, and The Verge summarized, that the FBI was able to recover incoming Signal message content from an iPhone’s notification database even after the app had been deleted. The important lesson is not that Signal encryption failed. It is that privacy can break at the edges when operating systems store previews and logs users do not expect.

    Why it matters: secure tools are only as private as the surrounding defaults. Notification previews, backups, and system-level logs can quietly create a second path to sensitive information.

    Richmond’s Flock records show officials thinking about liability and narrative at the same time

    Records reported by the Richmond Times-Dispatch indicate city officials were aware of racial-bias and liability concerns around Flock camera deployment while also discussing how to “saturate the public narrative” with success stories. That is a useful signal because it shows surveillance debates are often about public messaging and political management as much as technical capability.

    Why it matters: when officials are already thinking about liability, equity concerns, and narrative control, the public should ask whether real safeguards are keeping pace or whether the communications strategy is outrunning the governance strategy.

    OpenAI backs bill that would limit liability for catastrophic model harms

    Wired reports that OpenAI supported an Illinois bill that would limit when frontier AI firms can be sued for large-scale harms caused by their systems, so long as the companies did not act intentionally or recklessly and produced specified safety and transparency reports.

    Why it matters: this is an early warning sign about how the AI industry may try to shape the accountability rules around its own products before courts and lawmakers settle them. Liability is one of the few tools that forces organizations to internalize risk, so proposals to narrow it deserve close attention.

    Oakland County’s Flock drone pilot points toward the next surveillance layer

    A new Flock-linked drone pilot in Oakland County has already sparked privacy concerns. It fits a broader trend in which police technology is moving from fixed cameras and plate readers toward integrated aerial response, real-time feeds, and larger sensor networks.

    Why it matters: pilot programs often become normalized infrastructure faster than communities expect. That makes the pilot stage one of the most important moments for public scrutiny.

    Direction of travel: taken together, these signals suggest a common pattern: more location data, more integrated surveillance layers, and more pressure to soften accountability before the public has time to understand the system being built.

    A principle worth keeping in view
    If a human right is in the way of your innovative technology, the expected solution should be to modify your technology to respect that right, not to reduce the protections for that right.
    Technology and innovation must be in service of humanity, not the other way around.
    Safeguards are not obstacles to innovation. They are what make innovation fit for public life.


    Safeguards

    Safeguards section header

    Practical habits that lower risk. A safeguards section works best when it stays practical. This week’s strongest takeaways are about reducing exposure, treating infrastructure seriously, and refusing to let “pilot” become a shortcut around policy. Good safeguards are often less about dramatic technology than about narrowing access, shrinking visibility, and asking harder questions earlier.

    Keep industrial control systems off the open internet

    CISA warns that Iranian-affiliated actors are targeting internet-connected programmable logic controllers across U.S. critical infrastructure, including sectors like water, energy, and manufacturing. The advisory stresses that weak passwords, direct internet exposure, and loose remote access are doing much of the attacker’s work for them.

    Safeguard lesson: critical systems should not be exposed like ordinary web services. Public agencies and utilities should tighten remote access, eliminate default credentials, and treat operational technology as security infrastructure, not set-and-forget equipment.

    Treat home and small-office routers like real security devices

    The FBI’s IC3 says Russian GRU actors have been exploiting vulnerable routers worldwide, changing DNS settings and intercepting sensitive traffic tied to military, government, and infrastructure targets. The warning is a reminder that old or neglected routers can quietly become part of somebody else’s espionage chain.

    Safeguard lesson: update router firmware, replace unsupported devices, disable unnecessary remote administration, and stop treating network gear as invisible furniture. For many people, the router is part of the security perimeter whether they think of it that way or not.

    Treat surveillance pilots as real deployments

    EFF argues that “free” or subsidized surveillance technology often bypasses local scrutiny because it arrives as a trial, grant, or donated program rather than a fully debated procurement. But the privacy risks, data-sharing consequences, and normalization effects begin immediately, not after the pilot becomes permanent.

    Safeguard lesson: pilots should face real rules on retention, access logs, public notice, audits, sharing, and exit conditions before they begin. A temporary deployment can still create permanent habits.

    Hide notification content for sensitive messaging apps

    The Signal/iPhone reporting this week offers a simple citizen-facing reminder: if message previews are visible in notifications, they may be stored in places users do not expect. The convenience is real, but so is the privacy cost.

    Safeguard lesson: for sensitive messaging, reduce notification content or disable previews entirely. Strong encryption helps, but system defaults still matter.

    Bottom line: the best safeguards this week are not flashy. Keep critical systems off the open internet, treat routers as infrastructure, force real scrutiny at the pilot stage, and remember that privacy often fails first through defaults that feel convenient.

  • Signals & Safeguards Issue 4

    Issue 4 • Wednesday, April 8, 2026

    Signals & Safeguards newsletter masthead

    Privacy, surveillance, and cybersecurity developments that public officials should keep in view.


    At a glance

    • Section 702 is being defended by oversight institutions whose own credibility is under strain.
    • Voter-registration data may be moving into a broader federal citizenship-check pipeline.
    • Commercial data systems and multi-agency targeting centers show how state power can grow through private infrastructure and broad ideological categories.

    Main stories

    Section 702’s defenders are asking for trust while oversight gets weaker

    A new PCLOB staff report backs Section 702 just as the board’s own independence is under question. The report was issued after PCLOB had effectively been reduced to a single member, while critics argue even the reassuring FBI query numbers are incomplete. Lawmakers are being asked to trust oversight claims at the same moment the oversight system itself looks weaker.

    DOJ wants voter data, and DHS would help run the checks

    Justice Department lawyers told a court they plan to share voter-registration data obtained from states with DHS for citizenship checks. Once civic records begin flowing into federal verification systems, the issue is not only who can vote. It is who gets flagged, by whom, and with what chance to correct mistakes. The bigger warning sign is that an election-administration dispute can quickly become a broader federal data-sharing pipeline.

    ICE’s data power does not stop with government databases

    404 Media shows how Thomson Reuters’ CLEAR system has helped supply identity and records data used by ICE and may now feed Palantir systems used for targeting and analysis. Thomson Reuters markets CLEAR as an investigative platform built on a wide mix of public and proprietary records, including regulated driver and motor-vehicle data. The larger lesson is that enforcement power can grow through commercial data infrastructure long before the public sees a new law or a new government database. Sensitive information does not become less sensitive just because it reached government through a private intermediary first.

    Domestic-terror strategy grows broader, and more ideological

    The White House’s NSPM-7 uses categories like “anti-Americanism,” “anti-capitalism,” and “anti-Christianity,” and the FBI’s FY 2027 budget request says a new joint mission center spanning 10 agencies will help “proactively identify networks.” Ken Klippenstein’s article is sharper than the official documents, but the civil-liberties concern is real: broad ideological categories plus proactive targeting create real risk of viewpoint slippage and guilt by association.


    Early indicators worth tracking

    Signals section header

    These items point toward where surveillance systems, data practices, and governance fights may be heading next.

    LinkedIn is scanning browsers far more aggressively than most users would expect

    LinkedIn says it detects extensions to spot automation and scraping tools, but recent reporting says the site checks for more than 6,000 Chromium extensions and gathers additional device characteristics as well. Security justifications can be real and still expand platform visibility into the software running on a person’s device.

    “Incognito” privacy claims keep running ahead of reality

    A lawsuit against Perplexity alleges that user prompts and identifiers were shared with Google and Meta even when users chose “Incognito Mode.” Whether every allegation is proven or not, the broader lesson is already familiar: privacy labels can create expectations far stronger than the product actually delivers. Features that sound private may narrow some tracking while leaving platform logging or outside sharing intact.

    Facial-recognition errors are still ruining lives

    NBC highlights a recent case in which a woman was wrongly identified, jailed, and extradited because a face-matching system got it wrong. IEEE Spectrum helps explain why these harms persist: when databases get larger and the stakes get higher, false positives do not disappear. They scale.

    Dating-app photos ended up in a facial-recognition pipeline

    Match Group settled FTC claims that OkCupid shared millions of user photos and other personal data with Clarifai without adequately informing users. The lesson is simple: images tied to identity and location can become recognition inputs far beyond the platform where people originally shared them.

    Child-safety rules can become company-shaped identity rules

    A San Francisco Standard investigation found that the Parents & Kids Safe AI Coalition was funded entirely by OpenAI even as it presented itself as a broader child-safety effort. When firms help shape age-check rules, policymakers should ask whether a child-safety framework is quietly becoming a company-shaped identity system. Apple’s rollout, Malaysia’s proposal, and Turkey’s plan show how quickly that logic can widen.

    Government “modernization” can also mean stronger hidden triage systems

    WIRED reports that the IRS paid Palantir to improve a pilot system meant to identify “highest-value” audit, collections, and investigative cases across a maze of legacy systems. When agencies merge fragmented data into a stronger targeting layer, the key questions are fairness, explainability, and who gets flagged first. As the Brennan Center argues in the military context, vendors are increasingly helping shape the rules and procurement logic around the systems they want government to adopt.


    Practical habits that lower risk

    Safeguards section header

    The most useful safeguards this week share a common principle: reduce what systems can expose before someone else decides to search them.

    • Carry less sensitive data and assume travel devices can become exposure zones.
    • Use friction on purpose when it reduces the harm from seizure, compromise, or misuse.

    Build identity and access systems to ask for less data

    As more services move toward age checks, identity verification, and device-based trust decisions, policymakers should keep one question in view: what is the minimum information this system really needs? A system that asks for a government ID, a face scan, or permanent account linkage for routine access may solve one problem while creating another. The safest data is still the data a system never demanded in the first place.

    Ask vendors where AI is making decisions for them

    If AI systems are being woven into public-facing services, procurement tools, investigations, triage systems, or customer support, officials should not assume the risk stays inside the vendor. Ask where AI is being used in ways that affect judgment, ranking, eligibility, routing, or error correction, and what human review exists before those outputs shape decisions.

    Ask what a privacy feature actually protects against

    Many privacy features are real, but narrower than their names suggest. A tool that blocks some third-party tracking may still leave platform logs intact. An email-masking feature may protect against marketers while still leaving account records available to the platform and to government requests or investigations. Before trusting a feature, ask a simple question: does it protect against advertisers, the platform itself, outside data sharing, or government data demands?

    Treat dependencies like infrastructure, not convenience

    The Axios package compromise matters because Axios is one of the most widely used JavaScript libraries in modern web development, which means a single maintainer-targeted compromise can ripple across thousands of applications and organizations. Reuters and Microsoft’s follow-up reporting underscore the point: supply-chain attacks often begin with social engineering, not brilliant code exploits. For policymakers and institutions, the practical lesson is simple: slow down critical updates, verify unusual maintainer messages, rotate secrets after suspicious package incidents, and treat package ecosystems like infrastructure rather than background convenience.

  • Signals & Safeguards Issue 3

    Issue 3 • Wednesday, April 1, 2026

    Signals & Safeguards newsletter masthead

    Signals & Safeguards

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a Glance

    • ICE courthouse and airport tactics show how opaque rules and selective friction can make legal process itself part of the pressure.
    • Section 702 remains a live leverage point: Congress still has a chance to demand stronger safeguards before renewal.
    • Washington’s new ALPR law shows lawmakers can translate privacy concerns into concrete limits on collection, sharing, and access.

    ICE Courthouse Arrests Rested on Authority That Did Not Actually Apply

    Federal prosecutors said ICE had relied on 2025 guidance to justify immigration-court arrests even though the memo does not and never did apply there. That matters because the controversy is no longer only about an aggressive enforcement tactic. It is also a warning about what happens when coercive tactics move faster than their legal basis.

    Why it matters: when agencies act first and clarify authority later, public trust in courts and legal process erodes. Local officials should pay attention to enforcement systems pushing people into formal settings and then using those settings against them.

    Section 702 Renewal Is Becoming a Test of Whether Congress Will Demand Safeguards

    House leaders delayed action on Section 702, but the core fight remains the same: whether to extend a powerful surveillance authority without adding stronger protections such as a warrant requirement for searches involving Americans. The most important question is no longer whether the tool continues, but whether Congress will use rare leverage to insist on meaningful friction first.

    Why it matters: federal surveillance rules shape the broader privacy environment that local governments inherit. Weak guardrails at the top tend to normalize weaker oversight everywhere else.

    A Common Privacy Tool May Push Americans Into a Weaker Surveillance Category

    Lawmakers asked DNI Tulsi Gabbard to warn Americans that commercial VPN use may affect how intelligence agencies classify them. That is an unusually stark warning. A tool many people use for privacy may interact with surveillance rules in ways that leave an American outside the category of protections they thought they were gaining.

    Why it matters: rights become fragile when ordinary people cannot tell whether a protective behavior actually helps them or quietly pushes them into a weaker legal status.

    ICE Testimony in Oregon Describes Arrest Quotas and an “Elite” Targeting App

    In rare court testimony, ICE officers described verbal expectations of roughly eight arrests a day and the use of an app called Elite to identify places with a high “immigration nexus.” The combination matters as much as the tool itself: opaque data targeting paired with pressure to produce arrests can turn whole communities into enforcement targets.

    Why it matters: data-driven targeting and output pressure are not just federal concerns. They are warning signs any local official should notice when evaluating data-sharing, vendor tools, or joint enforcement relationships.

    Washington Puts Real Guardrails on License Plate Readers

    Washington enacted statewide ALPR rules that limit collection near sensitive locations, restrict sharing, require audits and transparency, and in some cases require warrants for access to private data. It is a useful reminder that oversight does not have to stay abstract.

    Why it matters: the most helpful surveillance stories are not always the most alarming ones. This one shows lawmakers can translate privacy concerns into actual rules on collection, retention, sharing, and access.

    Commercial Tracking Can Help Police Identify “Anonymous” Users

    Forbes reports investigators used Google cookie and account-linkage data to connect an anonymous account to another account used on the same device. The broader warning is that advertising and convenience infrastructure can quietly become investigative infrastructure.

    Why it matters: government surveillance capacity does not depend only on government-built tools. Commercial identifiers often do the linking work first, leaving police to obtain the results later.

    A Law in Arizona Would Require Public Approval Before Mass Surveillance Expands

    Arizona lawmakers are considering a bill that would require public approval before governments establish mass-surveillance networks and would impose tighter limits on retention and use. Even if it does not pass, it is a useful model because it treats surveillance expansion as something that should need democratic permission up front.

    Why it matters: it shows safeguards do not have to remain abstract. Public notice, voter approval, shorter retention, and bright-line limits are all concrete governance choices.

    Signals section header

    Signals

    Early indicators worth tracking

    These items are included because they point toward where surveillance systems, data practices, and governance fights may be heading next.

    • Systems sold as safety or convenience can quietly become search tools.
    • Official approvals only matter if they are real, legible, and enforced.

    FedRAMP Only Helps if “Authorized” Still Means Secure

    ProPublica reports federal reviewers had major doubts about Microsoft’s GCC High cloud service but FedRAMP approved it anyway. The broader concern is not just Microsoft. It is whether approval systems are too weak or too deferential to mean what officials imply they mean.

    A Facial-Recognition Lead Can Take on the Weight of Certainty

    CNN’s reporting on Angela Lipps’s months-long jail ordeal shows what can happen when an AI-linked identification lead enters a criminal case and institutions fail to slow down. The harm is not only the match itself, but the confidence the system seems to generate around it.

    The Pentagon’s Press Fight Is Really About Controlling Unsanctioned Inquiry

    A federal judge rejected earlier Pentagon restrictions, but the administration is still pressing a theory that trying to obtain “unauthorized” information can itself be a problem. That is a warning about governments trying to confine all inquiry to officially managed channels.

    Health Websites Can Become Disclosure Systems

    A federal judge allowed a privacy suit against Baystate Health to proceed after allegations that the hospital’s site shared health-related activity with Meta and Google. The story is a reminder that routine tracking code can become a sensitive-data leak when institutions treat analytics as harmless by default.

    AI Is Expanding the Afterlife of Digital Meetings

    404 Media’s reporting on WebinarTV suggests some Zoom calls have been recorded and repackaged as AI-generated podcasts. Even when a meeting is technically reachable online, that does not mean participants expect it to be harvested, transformed, and redistributed at scale.

    Voter-Registration Data May Be Moving Into the Federal Enforcement Pipeline

    NPR reports that Justice Department lawyers told a federal court they plan to share voter-registration data obtained from states with Homeland Security for criminal, immigration, and national-security uses. That is a warning about mission creep: records collected for one civic purpose can become part of a broader enforcement system once they are centralized.

    Editorial note: these items are included as forward-looking indicators rather than settled policy conclusions.

    Taken together, they suggest a common direction of travel: more hidden linkage, more secondary uses, and more pressure to treat convenience, safety, or administrative efficiency as sufficient justification for collecting and connecting sensitive data.

    Safeguards section header

    Safeguards

    Practical habits that lower risk

    The most useful safeguards this week share a common principle: reduce what systems can expose before someone else decides to search them.

    • Carry less sensitive data and assume travel devices can become exposure zones.
    • Use friction on purpose when it reduces the harm from seizure, compromise, or misuse.

    Treat Travel Devices Like Temporary Exposure Zones

    Travel with as little sensitive data as possible. Use travel-only devices or accounts when you can, disable biometrics, switch to a strong alphanumeric passcode, and power devices fully off before checkpoints. The simplest device-rights lesson is still the strongest one: a device cannot expose what it does not contain.

    Recent Cases Show Why That Matters

    The Verge reported that travelers returning from a Cuba aid trip had phones seized after secondary inspection. A U.S. consular alert also warns Hong Kong now criminalizes refusal to provide passwords or decryption assistance in some national-security investigations. The practical lesson is simple: device-rights expectations do not travel evenly across borders, airports, or jurisdictions.

    Use Higher-Friction Defenses on Purpose

    Apple says it is not aware of any successful mercenary-spyware compromise of a device using Lockdown Mode. That does not mean the feature is magic. It does suggest that extra friction can be worth it for high-risk users, and that policy terms like friction, separation, and deliberate limits on access are often safeguards, not inefficiencies.

    Harden Personal Accounts Too

    The breach of FBI Director Kash Patel’s personal email is a reminder that personal accounts used by senior officials still create public risk. Old emails, photos, and contact trails can carry leverage, targeting value, and reputational damage even when no official material is exposed.

    Keep Patching and Inventorying on Purpose

    Security leaders warned at RSA that AI is accelerating vulnerability discovery and may widen the gap between attackers and defenders. That makes asset visibility, software inventory, and timely patching more important — not less — in public institutions.

    Make Purpose and Retention Rules Visible

    Washington’s new ALPR law is a reminder that privacy protection is not only technical. Institutions should publish what they collect, how long they keep it, who can search it, and what activities are off-limits by rule rather than left to assumption.

    Bottom Line

    The strongest safeguards in this issue all reduce exposure before the moment of search — less data on devices, more friction around access, clearer legal boundaries, and fewer hidden assumptions about what systems can safely collect or connect.

    Signals & Safeguards is a living newsletter focused on surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    Signals & Safeguards footer graphic with privacy and security tagline
  • Signals & Safeguards Issue 2

    Issue 2 • Wednesday, March 25, 2026

    Signals & Safeguards newsletter masthead

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a Glance

    • The FBI’s current surveillance reach does not depend on advanced AI if agencies can already buy large pools of commercial data.
    • Kash Patel’s testimony sharpened the data-broker loophole debate and gave Wyden’s warning a more immediate national hook.
    • Section 702 renewal pressure continues even as critics argue warrantless searches of Americans’ data remain under-constrained.

    How the FBI Can Conduct Mass Surveillance — Even Without AI

    The Guardian’s analysis argues that agencies do not need futuristic AI to scale surveillance when they can already tap vast pools of commercial data. It works as a lead because it shifts the conversation back to powers that already exist, not hypothetical tools that may arrive later. The point is not that AI is irrelevant, but that the surveillance architecture needed to magnify harm is already in place.

    Why It Matters for Bend

    Privacy risks do not begin with city-owned tools. Commercial data markets can enlarge the surveillance ecosystem far beyond local procurement.

    Kash Patel Admits Under Oath FBI Is Buying Location Data on Americans

    At a Senate hearing, FBI Director Kash Patel said the bureau purchases commercially available information, and Senator Ron Wyden treated that as confirmation that the agency is buying Americans’ location data without a warrant. The testimony gives the data-broker loophole a clearer public face. It also turns a long-running privacy concern into a more immediate oversight question: if the information is sensitive enough to require judicial scrutiny in one context, why should procurement erase that protection in another?

    Why It Matters for Bend

    If government can buy sensitive location data it would otherwise need a warrant to obtain, local officials should think harder about the data-broker pipeline.

    Republican Speaker, Intel Chiefs Make New Push to Renew Surveillance Law

    Reuters reports that congressional leaders and intelligence officials are pressing for a quick, clean renewal of Section 702 even though critics say the core problem of warrantless searches of Americans’ data remains unresolved. The policy question is not only whether the authority continues, but whether it continues with meaningful friction, auditing, and restraint.

    Why It Matters for Bend

    Weak federal guardrails shape the broader privacy environment local governments operate in.

    Shared Pattern

    The strongest stories this week all point to the same lesson: surveillance capacity grows not only through new tools, but through easier access to data, wider search permissions, and fewer barriers between information systems.

    Signals

    Signals section header

    Early Indicators Worth Tracking

    These items are included because they point toward where surveillance systems, business incentives, or data architectures may be heading next.

    • Less visible vendor systems can become more powerful than the public realizes.
    • Business-model changes often become privacy-policy changes later.

    Hacker Says They Compromised Millions of Confidential Police Tips Held by US Company

    A reported breach of a platform used to search law-enforcement hotline messages is a warning about the fragility of outsourced public-safety data systems and the trust they depend on. When people share information through a supposedly confidential reporting channel, the security failure is not just technical; it can also deter future reporting.

    ELSAG SignalTrace

    Leonardo’s own product page shows how surveillance is moving beyond license plates. The system says it can correlate Bluetooth, Wi-Fi, RFID, vehicle-component, and phone-adjacent signals into an electronic fingerprint. In plain terms, that means a system may be able to recognize the cluster of electronic signals that tends to travel with a person or vehicle, even when no plate number is known.

    The Mask-Off Moment for Digital Identity

    This research-driven critique argues that digital identity systems can create brittle, over-centralized forms of verification and control. It fits here as a warning about where identity infrastructure can lead when resilience and restraint are treated as secondary.

    Electronic Surveillance Under Scrutiny

    SpyTalk frames the renewed fight over Section 702 as part of a broader warning: surveillance powers become more dangerous when they operate alongside expanded interagency data-sharing and weaker practical limits.

    Digital Surveillance Turns Everyday Devices Into Evidence

    IEEE Spectrum’s sensorveillance framing broadens the discussion beyond police-owned cameras. Phones, cars, apps, and connected devices create trails that can become evidence later. That makes ordinary consumer technology part of the surveillance conversation whether people think of it that way or not.

    The Rise of the Ray-Ban Meta Creep

    WIRED’s reporting on smart glasses shows how wearable cameras can normalize ambient surveillance before consent norms and safeguards catch up. When recording becomes fashionable, discreet, and easy to dismiss as ordinary consumer tech, the social pressure against constant capture weakens.

    Editorial note: these items are included as forward-looking indicators rather than settled policy conclusions.

    Taken together, they suggest a common direction of travel: more linkage, more inference, and more pressure to treat convenience or growth as sufficient justification for collecting and connecting sensitive data.

    Safeguards

    Safeguards section header

    Practical Habits That Lower Risk

    A safeguards page works best when it is practical. These are the protections, governance habits, and design choices that stood out while sourcing this issue.

    • Good safeguards usually depend on less data, cleaner boundaries, and fewer shortcuts.
    • Better defaults are often more important than dramatic new tools.

    Protect Messaging Accounts Like Infrastructure

    The FBI and CISA say recent Russian campaigns targeted messaging-app accounts through phishing and account compromise, not by breaking encryption.

    Treat verification codes, QR links, unexpected support messages, and rushed login prompts as suspicious until verified out of band.

    Never share a PIN or 2FA code. Review linked devices regularly and report suspected phishing quickly.

    That posture is especially important for officials, staff, journalists, and advocates whose accounts may be targeted for access rather than for disruption.

    Know Where Sensitive Data Lives Before You Promise to Protect It

    NIST emphasizes discovering, identifying, and labeling sensitive unstructured data before it is lost, overshared, or mishandled.

    For local government, this is a governance safeguard as much as a cybersecurity safeguard: if no one knows where citizen data resides, retention limits and access controls become guesswork.

    Data inventories are not glamorous, but they are often the difference between enforceable privacy rules and aspirational ones.

    Design Identity and Verification Systems to Ask for Less

    NIST’s mobile driver’s license guidance is a reminder that verification systems can be designed to request less data rather than more.

    The safest personal information is often the information a system never demanded in the first place.

    A strong safeguard question for policymakers is simple: what minimum information does this transaction actually require?

    What Regulators Actually Check

    A useful governance reminder: protections must be visible and real, not merely claimed. Audits and enforcement often focus on what users actually experience, not what an organization says its system does.

    For policymakers, the lesson is simple: require proof, symmetry, and clear choices instead of trusting compliance language at face value.

    In practice, that means asking whether people can refuse, opt out, or correct errors as easily as they can be tracked, profiled, or nudged.

    Use Higher-Friction Defenses on Purpose

    AP’s Lockdown Mode explainer is a good citizen-facing example: some security features intentionally add friction because convenience is not always the highest value.

    That mindset also applies to public systems. Friction, separation, and limited access are sometimes privacy safeguards, not inefficiencies.

    In a policy context, that can mean narrower permissions, shorter retention, fewer integrations, and more deliberate approvals.

    Bottom Line

    Strong safeguards are usually boring by design — better data mapping, less data collection, cleaner account hygiene, and more deliberate limits on access. Signals & Safeguards is a living newsletter focused on surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    Signals & Safeguards footer graphic with privacy and security tagline
  • Signals & Safeguards Issue 1

    Issue No. 1 | Council Introduction Edition | March 2026

    A concise weekly newsletter for Bend City Council, the City Manager, Oregon legislators, and committee members following surveillance, cybersecurity, and public-sector technology oversight.

    At a Glance

    • Oregon’s ALPR debate shows that safeguards can still leave practical gaps even after legislation passes.
    • Surveillance data often drifts beyond its original purpose, and when it is wrong, ordinary people carry the harm.
    • The larger trend is that cameras, wireless systems, and commercial vendors can all expand surveillance capability faster than public safeguards evolve.

    1) Oregon’s ALPR Debate Shows How Safeguards Can Still Leave Gaps

    Reporting from Lookout Eugene-Springfield says Oregon lawmakers took steps this session to limit how automated license plate reader data can be shared, especially after the Eugene controversy. But critics still see major gaps, including the need for a clearer end-to-end encryption standard. That matters because if the rule is vague, the public may be told the data is protected while vendors or third parties still have too much practical access to readable information.

    Why This Matters for Bend

    • Guardrails matter most before a system becomes normal and hard to unwind.
    • Encryption, retention, vendor access, and sharing limits should be written clearly enough that they cannot be quietly stretched later.
    • Local control is only real if local governments adopt specific restrictions rather than relying on broad promises from vendors.

    2) Plate-Reader Data Can Drift Into Everyday Administrative Decisions

    NBC Chicago and The Register report that an Illinois school district used license-plate reader data in a residency dispute, and a mother says the records were misleading because her car had been loaned to a family member. That example matters because it shows two risks at once: mission creep and error. Data collected through surveillance infrastructure can migrate into everyday decisions far outside its original justification, and when it is wrong, the harm falls on ordinary people.

    Why This Matters for Bend

    • Mission creep often arrives through ordinary administrative uses, not dramatic headline cases.
    • An inaccurate or misleading surveillance record can still carry real consequences for a family.
    • Clear authorized-use rules and meaningful oversight are necessary before secondary use becomes normalized.

    3) Surveillance Is Moving Beyond Visible Cameras

    New research projects are showing that people can sometimes be tracked or analyzed without a traditional camera at all. The RuView repository is best understood as a public warning sign, not a finished city product: it points to a future in which wireless signals may reveal presence, movement, or other sensitive details even when no obvious camera is in view. For lawmakers, the lesson is simple: if policy only regulates cameras, it may miss the next generation of sensing systems.

    Why This Matters for Bend

    • Rules should focus on what a system can infer or collect, not only what the hardware is called.
    • A visible camera is no longer the only way a space can be monitored.
    • Procurement review should ask what a system could become after deployment, not just what it does on day one.

    4) Traffic and Security Cameras Can Become Intelligence Infrastructure

    Recent reporting from TechCrunch and WIRED says hacked traffic cameras and other civilian systems may have helped outside actors monitor movement and identify useful information on the ground during the war against Iran. That is a warning for cities: systems that look routine in peacetime can become intelligence assets if they are compromised or overexposed.

    Why This Matters for Bend

    • A camera system is not just a public-safety tool. It is also a map of routines, locations, and infrastructure.
    • The more data a system stores, and the more people who can access it, the more damage a breach can do.
    • Questions about retention, segmentation, vendor access, and audit logs are security questions, not just privacy questions.

    5) Commercial Surveillance Vendors Are Lowering the Barrier to Advanced Intrusion

    According to Google’s latest zero-day review, commercial surveillance vendors were linked to more previously unknown software flaws exploited in the wild than traditional state-sponsored cyber espionage groups. For policymakers, the practical point is that highly sensitive surveillance and hacking capability is no longer limited to a few intelligence services. More of it is now available through a private market.

    Why Policymakers Should Pay Attention

    • Vendor oversight is not only about price and convenience. It is also about trust, security practices, and what kinds of capabilities a company may be building or enabling.
    • A system that looks narrow at the time of purchase can sit inside a much larger surveillance ecosystem.
    • Public agencies should assume capability can spread faster than law and policy catch up.

    Watch Item

    Identity-Verification Data Can Become a Public Risk When Security Fails

    Cybernews reported that an unsecured database linked to identity-verification company IDMerit exposed roughly one billion records across 26 countries, including more than 203 million U.S. records. Reported exposed information included national ID numbers, full names, addresses, phone numbers, and other identity-verification data. The broader lesson is that large surveillance and verification systems do not only create collection risk. They also create security risk when sensitive data is centralized and poorly protected.

    Shared Pattern Across This Issue

    Across all six items, the common thread is that systems which look routine in procurement or operations can become much more powerful — or much more dangerous — than they first appear. That is why meaningful oversight should include narrow authorized uses, limited retention, strong access controls, logged searches, audits, encryption, secure update practices, and contract language that anticipates future capability growth. Signals & Safeguards is designed as a concise briefing on surveillance, cybersecurity, and public-sector technology oversight.