https://www.theregister.com/2023/03/04/dhs_secret_service_ice_stingray/ [user] [user] Sign in / up The Register(r) -- Biting the hand that feeds IT [magn] [burg] [burg] Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal Tech (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Vendor Voice Vendor Voice Vendor Voice All Vendor VoiceAmazon Web Services (AWS) Business TransformationDDN Google Cloud for Startups (X) Resources Resources Whitepapers Webinars Newsletters [front] Security 10 comment bubble on white Secret Service, ICE break the law over and over with fake cell tower spying 10 comment bubble on white Investigations 'at risk' from sloppy surveillance uncovered by audit probe icon Thomas Claburn Sat 4 Mar 2023 // 01:00 UTC # The US Secret Service and Immigration and Customs Enforcement (ICE) agencies have failed to follow the law and official policy regarding the use of cell-site simulators, according to a government audit. Cell-site simulators (CSS), also known as Stingrays or IMSI Catchers, are devices that serve as decoy cell towers. They're used by law enforcement, intelligence services, and others to intercept metadata or communications, and triangulate a phone's location. Essentially, your handset connects to the nearby tower, think it belongs to a telco, but in fact, it's a temporary mast set up by the Feds to snoop on devices within range. For years, these devices have elicited criticism from civil rights groups and legislators who argue that they violate Fourth Amendment protection against unreasonable search and seizure. The government insists it will only use this type of kit in line with existing rules and restrictions, but it appears that is not the case. [front] The Department of Homeland Security (DHS) Office of the Inspector General (OIG) looked at CSS deployment by the Secret Service and ICE and found, "Secret Service and ICE HSI [Homeland Security Investigations] did not always adhere to Federal statute and CSS policies when using CSS during investigations involving exigent circumstances." [front] [front] The OIG audit report [PDF] also found that "ICE HSI did not adhere to Department privacy policies and the applicable Federal privacy statute when using CSS." The audit was originally undertaken to look at how the agencies adhered to policies on cell-phone surveillance and commercial location-sharing databases, but DHS OIG now is dealing with those two separately. The phone surveillance report offers six recommendations to help the agencies comply with their legal and policy obligations. But annoyingly it redacts statistical data about the number of investigations utilizing CSS devices in 2020 and 2021. [front] Government investigators are supposed to get a court order at the least to use a pen register (devices that record incoming and outgoing phone numbers when calls are made), except under exigent circumstances - the so-called ticking time bomb scenario. But as the OIG report notes, the two organizations often failed to do that. "The fact that government agencies are using these devices without the utmost consideration for the privacy and rights of individuals around them is alarming but not surprising," said EFF Policy Analyst Matthew Guariglia in a blog post on Thursday. "The federal government, and in particular agencies like HSI and ICE, have a dubious and troubling relationship with overbroad collection of private data on individuals." Guariglia argues the OIG should release the statistical data so that the public can better understand how often CSS devices play a role in investigations. We make the rules, we break the rules In October 2015 Alejandro Mayorkas, then Deputy Secretary of DHS and currently Secretary of DHS, issued a policy memorandum [PDF] stating that the department "must use cell-site simulators in a manner that is consistent with the requirements and protections of the Constitution, including the Fourth Amendment, and applicable statutory authorities, including the Pen Register Statute." By 2017, the Secret Service and ICE had each formulated policies incorporating the DHS directive. [front] The Department of Justice says [PDF] that while it has in the past "obtained authorization to use a cell-site simulator by seeking an order pursuant to the Pen Register Statute" - which does not require a probable cause warrant - "as a matter of policy, law enforcement agencies must now obtain a search warrant supported by probable cause and issued pursuant to Rule 41 of the Federal Rules of Criminal Procedure (or the applicable state equivalent)." But there are various exceptions when a warrant is not required and CSS deployment is governed by the rules for pen registers. Exceptions include: "the need to protect human life or avert serious injury; the prevention of the imminent destruction of evidence; the hot pursuit of a fleeing felon; or the prevention of escape by a suspect or convicted fugitive from justice." And there's also an exception when the law doesn't require a warrant and obtaining one would be impractical. Given this legal inconsistency, it's not always obvious whether CSS deployment was done lawfully. In a 2017 decision in Prince Jones v. US, an appeals court found "the government violated the Fourth Amendment when it deployed the cell-site simulator against [plaintiff Prince Jones] without first obtaining a warrant based on probable cause." And the following year, the US Supreme Court ruled 5-4 in US v. Carpenter that the warrantless search and seizure of cell-site data violated the Fourth Amendment. * US border cops harvest info from citizens' phones, build massive database * Those fake spying cell towers in Washington DC? Ex-intel staffers claim they're Israeli * TSA to expand facial recognition across America * Ex IT chief at Homeland Security watchdog stole US govt software to pirate Legislators recently have tried to make CSS usage clearer. In 2021, US Senator Ron Wyden (D-OR) and a bipartisan group of other lawmakers introduced a bill, the Cell-Site Simulator Warrant Act, requiring the government to obtain a warrant to deploy a CSS device. "Current federal, state, and local policies regulating Stingrays are confusing and inconsistent, opening the door to abuse and unconstrained, invasive surveillance by law enforcement," the Project on Government Oversight (POGO) said in support of the bill. The bill never made it out of committee. Freddy Martinez, a senior researcher with POGO, told The Register in a phone interview that since the Carpenter decision, most jurisdictions have some sort of warrant requirement. But the report, he said, indicates that there's still a lot of confusion about differences between historical cell-site data, real-time cell-site data, and emergency access, and so on. "This report really does speak to the problems of unclear statutes," he said. "It would be easy if Congress just passed a law that said you have to get a warrant to use this equipment." Martinez also observed that the report points out the problem with federal authorities relying on local partners to do the necessary paperwork. "They're not doing the paperwork that they need to be doing and they're putting cases at risk," he said. (r) Get our Tech Resources # Share Similar topics * Federal government of the United States * Mobile * Privacy More like these x Similar topics * Federal government of the United States * Mobile * Privacy * Surveillance Narrower topics * cookies * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Federal Aviation Administration * GPS * Immigration and Nationality Act of 1965 * IRS * NASA * National Highway Traffic Safety Administration * National Institute of Standards and Technology * National Labor Relations Board * NCSAM * NHTSA * NSO Group * Privacy Sandbox * Telecommunications Act of 1996 * United States Department of Defense * United States Department of Justice * US Securities and Exchange Commission Broader topics * Government * Security * United States of America Similar topics # Share 10 comment bubble on white COMMENTS Similar topics * Federal government of the United States * Mobile * Privacy More like these x Similar topics * Federal government of the United States * Mobile * Privacy * Surveillance Narrower topics * cookies * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Federal Aviation Administration * GPS * Immigration and Nationality Act of 1965 * IRS * NASA * National Highway Traffic Safety Administration * National Institute of Standards and Technology * National Labor Relations Board * NCSAM * NHTSA * NSO Group * Privacy Sandbox * Telecommunications Act of 1996 * United States Department of Defense * United States Department of Justice * US Securities and Exchange Commission Broader topics * Government * Security * United States of America TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Thought you'd opted out of online tracking? Think again Probe shows that - to absolutely no-one's surprise - big biz isn't playing ball Personal Tech3 Mar 2023 | 83 Google lets a few Android devices into its Privacy Sandbox Chocolate Factory's ad tech renovation is moving ahead, like it or not Security14 Feb 2023 | 9 Texas mulls law forcing ISPs to block access to abortion websites Whatever happened to small government that stays out of our lives Personal Tech4 Mar 2023 | 38 Hybrid working is here to stay, but is the IT up to speed? With more employees than ever choosing where they work, the need for PCs fit for purpose has intensified Sponsored Feature [front] Mozilla says 80 percent of Google Play's app safety labels are inaccurate Labelling scheme offers developers easy loopholes to play down personal info spreading Networks24 Feb 2023 | 34 Pushers of insecure software in Biden's crosshairs Analysis Just-revealed US cybersecurity strategy 'has fangs' for catching crafty criminals and crummy coders Security3 Mar 2023 | 18 German Digital Affairs Committee hearing heaps scorn on Chat Control Proposal to break encryption to scan messages for abuse material challenged as illegal and unworkable Security3 Mar 2023 | 19 Virtual reality telemetry means you can virtually kiss goodbye to privacy Exclusive Boffins find they can identify VR players just from head and hand movements Personal Tech18 Feb 2023 | 34 EU lawmakers argue against signing US data-transfer pact Committee: Something about complaints process being dealt with in total secrecy doesn't sit right Security17 Feb 2023 | 58 Funnily enough, FDA forbids Elon Musk's Neuralink human experiments It's still coming soon ... just like it was in 2019, and 2020, and 2021, and 2022 Science2 Mar 2023 | 24 Havana Syndrome definitely (maybe) not caused by brain-scrambling energy weapons Pre-existing mental health issues and the stress of working in Cuba are more likely culprits Bootnotes2 Mar 2023 | 28 US Marshals Service leaks 'law enforcement sensitive information' in ransomware incident It's not just another data breach when the victim oversees witness protection programs Cyber-crime28 Feb 2023 | 5 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * T's & C's * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2023 no-js