WK 14 WORD 400

profileDrAwesome
Wk14-YourSecretStingray_sNoSecretAnymoreTheVanishingGovernmentMonopolyOverCellPhoneSurveillance.pdf

1

Your Secret StingRay’s No Secret Anymore: The Vanishing Government Monopoly over Cell Phone Surveillance and its Impact on National

Security and Consumer Privacy

Stephanie K. Pell1 & Christopher Soghoian2

“. . . [T]hou wilt not trust the air with secrets.” — Shakespeare, Titus Andronicus.3

I. INTRODUCTION During a 1993 Congressional oversight hearing on the integrity of telephone networks,4 security researcher Tsutomu used a “software hack” to turn an analog cellular phone into a scanner that enabled all present in the hearing room to hear the live conversations of nearby cellular phone users.5 Shimomura had been granted congressional immunity to perform this demonstration under the watchful gaze of a nearby FBI agent.6 The event was a practical demonstration of what Subcommittee Chairman Ed M key c lled “t e s n ste s de of cybe sp ce.”7 The demonstration illustrated a significant security vulnerability impacting then- widely used analog cellular phone networks: calls were not encrypted as they were transmitted over the air and could, therefore, be intercepted with readily available equipment, such as an off-the-shelf radio scanner or a modified cellular phone.

The authors wish to thank Matt Blaze, Ian Brown, Alan Butler, Susan Freiwald, Allan Friedman, Jean- Pierre Hubaux, Eric King, Susan Landau, Linda Lye, Aaron K. Martin, Valtteri Niemi, Karsten Nohl, Brian Owsley, Christopher Parsons, Christopher Prince, John Scott-Railton, Greg Rose, Seth Schoen, Jennifer Valentino-DeVries, David Wagner, Nicholas Weaver, several individuals who have asked to remain anonymous, and the attendees of our session at the 2013 Privacy Law Scholars Conference. 1 Principal, SKP Strategies, LLC; Non- es dent Fell w t t nf d L w c l’s Cente f Inte net nd Society; former Counsel to the House Judiciary Committee; former Senior Counsel to the Deputy Attorney General, U.S. Department of Justice; former Counsel to the Assistant Attorney General, National Security Division, U.S. Department of Justice; and former Assistant U.S. Attorney, Southern District of Florida. 2 Principal Technologist, Speech, Privacy & Technology Project, American Civil Liberties Union and Visiting Fellow, Information Society Project, Yale Law School. The opinions expressed in this article e t s t ’s l ne, nd d n t eflect t e ff c l p s t n f s e pl ye . 3 William Shakespeare, Titus Andronicus, act IV, scene II, l. 1862. 4 Telecommunications Network Security: Hearing Before the Subcomm. On Telecommunications and Finance of the H Comm. On Energy and Commerce, 103rd Cong. (April 29 & June 9, 1993) [hereinafter Telecommunications Network Security Hearing]. 5 Id. at 8-9. 6 See Immunity Needed; Markey Panel Sees Dark Side of Electronic Frontier, Communications Daily, April 30, 1993, https://w2.eff.org/Privacy/Newin/Cypherpunks/930430.communications.daily 7 See Telecommunications Network Security Hearing, supra note **, Opening Statement of Chairman Markey at 4.

2

Although the threat demonstrated by Shimomura was clear, Congress and the Federal Communications Commission (FCC) took no steps to mandate improvements in the security of analog cellular calls.8 Such a technical fix would have required wireless carriers to upgrade their networks to support more secure telephone technology, likely at significant cost.9 Instead, Congress outlawed the sale of new radio scanners capable of intercepting cellular signals and forced scanner manufactures to add features to their products to prevent them from being tuned to frequencies used by analog cell phones.10 This action by Congress, however, did nothing to prevent the potential use of millions of existing interception-capable radio scanners already in the homes and offices of Americans to intercept telephone calls.11

8 See Telecommunications Network Security Hearing, supra note **, Statement of Chairman Markey t 12 (“L st ye we p ssed leg sl t n t b n sc nne s, b t we cle ly d d n t b n cell l p nes. However, cellular phones can be reprogrammed as a scanner with a relatively rudimentary kn wledge f t e tec n l gy. Tens f t s nds f pe ple kn w w t d t.”). In s b ss n t the FCC, the cellular industry association opposed proposals for the FCC to focus on the cellular interception vulnerabilities, rather than the availability of radio scanners capable of intercepting cellular phone calls. See Cellular Telecommunications Industry Association (CTIA) Reply Comments on Amending of Parts 2 and 15 to Prohibit Marketing of Radio Scanners Capable of Intercepting Cellular Telephone Conversations at 4 (March 8, 1993), http://apps.fcc.gov/ecfs/document/view;jsessionid=fTGkSn3c0CsJjGhv2ts5DQQktvyhfXkHpW2JPnr 9pPhxQ9sC88Cp!-1864380355!1357496456?id=1120040001 [hereinafter CTIA Reply Comments] at 4 (“R t e t n p p s ng t st engt en t e C ss n's p p sed les, weve , t ese p t es would have the Commission weaken or abandon its proposals and place the burden solely on cellular carriers or manufacturers to protect the pr v cy f cell l telep ne c lls… With the enactment of ect n 403( ), t e t e f s c n g ent s p st.”) 9 See Craig Timberg and Ashkan Soltani, By cracking cellphone code, NSA has capacity for decoding private conversations, Washington Post, December 13, 2013, available at http://www.washingtonpost.com/business/technology/2013/12/13/e119b598-612f-11e3-bf45- 61f69f54fc5f_st y. t l (“Upg d ng n ent e netw k t bette enc ypt n p v des s bst nt lly more privacy for users . . . But upgrading entire networks is an expensive, time-consuming nde t k ng.”). See also Babbage infra note ** (currently fn 256). Such network upgrades would also have neutralized analog interception devices then in use by US government agencies. 10 See FCC Report and Order, Amendment of Parts 2 and 15 to Prohibit Marketing of Radio Scanners Capable of Intercepting Cellular Telephone Conversations, adopted April 19, 1993, available at http://apps.fcc.gov/ecfs/document/view;jsessionid=CyspSn3R1KqpKlzyc9pwb5GyypnrQ4nnGMqFq tNpQyFYbhWZ2r1c!1357496456!-1864380355?id=1145780001, made in response to Sec. 403 of the Telephone Disclosure and Dispute Resolution Act, Pub. L. 102-556 (1992); codified at § 47 U.S.C. 302a(d) (requiring that within 180 days of enactment, the FCC shall prescribe and make effective regulations denying equipment authorization). However, as the FCC made clear in its report, this p b t n d es n t pply t c p n es t t “ ket[] [ n l g cell l nte cept n] tec n l gy t l w enf ce ent genc es.” See FCC Report and Order, at 7. Such a law enforcement exemption had been requested by the Harris Corporation, and supported by the cellular industry association. See CTIA Reply Comments, supra n te ** t 8 (“CTIA s pp ts t e H s C p t n's eq est t t t e Commission modify its proposed rules to clarify that scanning receivers that receive cellular t ns ss ns … y c nt n e t be n f ct ed f s le t [l w enf ce ent]”). 11 See CTIA Reply Comments, supra n te ** t 3 (“A n be f c ente s g e that the Commission's proposed rules are flawed because they will not effectively safeguard the privacy of cellular calls. These commenters point out that millions of scanning receivers capable of tuning cellular frequencies are already in use, and that such receivers will remain available for sale for n t e ye .”) See also Summary of Testimony Of Thomas E. Wheeler, Cellular Telecommunications

3

In 1997, four years after the FCC enacted Congressionally mandated regulations banning the sale of scanning equipment capable of intercepting cellular signals,12 a couple from Florida recorded a conference call between several senior Republican politicians, including then Speaker of the House Newt Gingrich, which they were able to intercept because one of t e c ll’s p t c p nts w s using a cellular phone.13 Although the couple did not intend to impact US communications policy when they turned on their radio scanner, their act was high-profile proof t t C ng ess’s response to the analog interception threat was not successful.14 What ultimately fixed the analog phone interception problem was not further congressional action but rather, t e w eless nd st y’s migration away from easily intercepted analog phone technology to digital cellular phones—a decision motivated in part by the increase in cellular phone cloning fraud.15 Digital phone conversations were, at the time, far less likely to be intercepted because the necessary equipment was prohibitively expensive and thus available to fewer potential snoops.16 Governments with significant financial resources, however, have owned and used cellular phone surveillance equipment for quite some time. Indeed, for nearly two Industry Association, February 5, 1997 at 1, House Commerce Committee, Subcommittee on Telecommunications, Trade and Consumer Protection. 1997 WL 49420 [hereinafter Summary of Wheeler testimony], (“[T]rying to ban a specific type of eavesdropping gear after it has already bec e w dely v l ble s d ff c lt.”). 12 See FCC Report and Order, supra note 10. 13 The participants of the call—who included Republican Majority Leader Dick Armey, Republican Whip Tom Delay, New York Congressman Bill Paxon John Boehner—were discussing an investigation by the Congressional Ethics Committee of Gingrich. The Florida couple gave the recording to the ranking Democratic member of the Ethics Committee (and thus the leader of the Gingrich investigation). See The Gingrich Cellular Phone Call, PBS NewsHour, January 14, 1997, http://www.pbs.org/newshour/bb/politics/jan-june97/cellular_01-14.html. 14 This was not the only opportunity in 1997 for Congress to observe that cellular communications were still not secure. See Committee Report, for H.R. 2396 the Wireless Privacy Enhancement Act of 1998, http://www.gpo.gov/fdsys/pkg/CRPT-105hrpt425/pdf/CRPT-105hrpt425.pdf at 5 (“T e Subcommittee on Telecommunications, Trade, and Consumer Protection held a hearing on cellular p v cy n Feb y 5, 1997…. P t t e w tnesses’ test ny, tec n l g c l de nst t n w s conducted to highlight the ease w t w c sc nn ng eq p ent c n be ‘‘ e d ly lte ed’’ t nte cept cell l c n c t ns.”). 15 Cell p ne cl n ng s p cess by w c ne p ne’s n q e cc nt n be c ld be c pt ed and programmed into another phone for purposes of billing one p ne’s c lls t n t e p ne. See generally Jeri Clausing, Congress Moving Quickly to Try to Curb Cell Phone Abuses, New York Times, March 2, 1998, available at http://www.nytimes.com/1998/03/02/business/congress-moving- quickly-to-try-to-curb-cell-phone-abuses.html. 16 See David Wagner, Bruce Schneier and John Kelsey, Cryptanalysis of the Cellular Message Encryption Algorithm, Advances in Cryptology - CRYPTO'97, available at http://www.schneier.com/paper-c e .pdf (“[T] e l test d g t l cellp nes c ently offer some weak protection against casual eavesdroppers because digital technology is so new that inexpensive d g t l sc nne s ve n t yet bec e w dely v l ble.”). See also Committee Report, for H.R. 2396 supra n te 13 t 3 (“While digital cellular and PCS are not immune from eavesdropping, they are currently more secure than analog cellular because the equipment for intercepting digital calls is vastly more expensive and complex than existing, off-the-shelf scanners that intercept analog communications (e.g., $200 vs. $10,000–$30,000).”).

4

decades, US federal, state and local law enforcement agencies have employed sophisticated cellular surveillance equipment that exploits vulnerabilities in cellular networks. Once only accessible to a few global powers at six-figure prices, similar technology is now available to any government—including those with a history of spying in the United States—and to any other interested buyer from surveillance companies around the world, often for as little as a few thousand dollars per device.17 Moreover, hobbyists can now build less advanced but functional interception equipment for as little as $100.18 The normal course of economics and innovation has destroyed the monopoly a select group of global powers once enjoyed over digital cellular surveillance technology, rendering surreptitious access to cellular communications as universally available as it once was in the analog world: surveillance has, once again, become democratized, this time with a much more expansive set of capabilities. During Congressional testimony in 1997, current Federal Communications Commission (FCC) Chairman Tom Wheeler, then the president of the cellular industry association (CTIA), warned the Committee of this outcome: “Unless Congress takes a forward-looking approach, history will likely repeat itself as digital scanners and decoders, though expensive now, drop in price in the future.”19 Mr. Wheeler’s prescient warning has come true. Although the technology has changed, we are rapidly approaching a future of widespread interception that feels much like the past, but with a much larger range of public and private actors with more diverse motives for snooping. Whoever employs this technology can obtain direct, unmediated access to information about and from a cellular phone without any aid from a wireless provider.20 In some cases, this technology can even intercept the contents of cellular phone calls, text messages and other communications data transmitted to and from the phone.21 In this Article, we will argue that policy makers did not learn the right lessons from the analog cellular interception vulnerabilities of the 90s: that is, the communications of Americans will only be secured through the use of privacy enhancing technologies like encryption, not with regulations prohibiting the use or sale of interception technology. Nearly two decades after Congress passed legislation intending to protect analog phones from interception by radio

17 See infra Part V. 18 See infra Part V. 19 See Summary of Wheeler Testimony, supra note ** at 2. 20 See John Kelly, Cellphone data spying: It's not just the NSA, USA Today, December 8, 2013, available at http://www.usatoday.com/story/news/nation/2013/12/08/cellphone-data-spying-nsa- p l ce/3902809/ (“T e t ng y c n g b s e d t f cellp nes n e l t e nd w t t g ng t g t e w eless se v ce p v de s nv lved.”) See also Ability, IBIS II - In-Between Interception System - 2nd Generation, http://www.interceptors.com/intercept-solutions/Active-GSM- Inte cept . t l (“T e IBI –II is a stand-alone solution for off the air interrogation / interception / monitoring / deception of tactical GSM communication, in a seamless way, without any cooperation with the network provider.”) (e p s s dded). 21 See infra Part **.

5

scanners,22 the American public is poised, quite unknowingly, at the threshold of a new era of communications interception that will be unprecedented in its pervasiveness and variety. Foreign governments, criminals, the tabloid press and curious individuals with innumerable private motives can now leverage longstanding security vulnerabilities in our domestic cellular communications networks that were previously only exploitable by a few global powers. In spite of the security threat posed by foreign government and criminal use of cellular interception technology, US government agencies continue to treat practically everything about it as a closely guarded “source and method,”23 shrouding the technical capabilities, limitations and even the name of the equipment they use from public disclosure. The source and method argument is invoked to protect law enforcement genc es’ wn se f cell l nte cept n tec n l gy by preventing criminal suspects from learning how to evade surveillance.24 This secrecy is not only of questionable efficacy for that purpose, however, but it comes at a high collateral cost in that it keeps the American public in the dark about cellular network vulnerabilities and thus generally unaware of the need to secure their private communications. Indeed, at a time when cyber security threats are a top congressional priority, there has been no public discussion by policy makers about the exploitable vulnerabilities latent in our cellular networks and no corresponding policy debate about how to protect private communications from those threats. If the US and its close allies had a monopoly over this technology, policy makers could argue that certain national security interests furthered by the use of the technology—and thus the need to maintain the secrecy of all related information— trump the need to inform the American public about the vulnerability of cellular communications. This Article, however, dispels the myth that this technology is, in fact, secret at all. Indeed, it has been the subject of front page stories in leading newspapers,25 has been featured in Hollywood movies,26 television dramas27 and

22 See § 403 of the Telephone Disclosure and Dispute Resolution Act, Pub. L. 102-556 (1992); codified at § 47 U.S.C. 302a(d). 23 See infra Part IV. 24 See infra Part **. 25 See Jennifer Valentino-DeVries, 'Stingray' Phone Tracker Fuels Constitutional Clash, WALL ST. J., Sept. 22, 2011, http://online.wsj.com/article/SB10001424053111904194604576583112723197574.html. See also Ellen Nakashima, Little-known surveillance tool raises concerns by judges, privacy activists, The Washington Post, March 27, 2013, http://www.washingtonpost.com/world/national-security/little- known-surveillance-tool-raises-concerns-by-judges-privacy-activists/2013/03/27/8b60e906-9712- 11e2-97cd-3d8c1afe4f0f_story.html. 26 See Zero Dark Thirty (movie), at 83:00 27 See The Wire: Middle Ground, e s n 3, Ep s de 11 t XXX (HBO telev s n b dc st) (“Re e be those analog units we used to use to pull cell numbers out of the air? The C. F. something-something Ye , Cell F eq ency Ident f c t n Dev ce.” “T e t gge f s , ye .” “T t ne, t c ld fl g n be .” “R g t, b t t e ld n l g c nes? We sed t ve t f ll w t e g y und stay close while he sed t e p ne.” “New d g t ls b ng, we j st p ll t e n be g t ff t e cell t we s.”)

6

more ominously, can be purchased over the Internet from one of many non-US based surveillance technology vendors or even built at home by hobbyists. We therefore argue that the risks to the American public arising from the US g ve n ent’s continued suppression of public discussion of vulnerabilities in our cellular communications networks that can be exploited to perform unmediated interception outweigh the now-illusory benefits of attempting to keep details of the surveillance technology secret. Congress should address these network vulnerabilities and the direct interception techniques they enable, as well as the necessity for responsive privacy enhancing technologies like strong encryption,28 as part of the larger cyber security debate, to which they are all inextricably linked. To date, however, this policy debate is not occurring, which is not beneficial either to privacy or cellular network security. Part II of this Article begins by naming this “secret” interception technology and describing its capabilities. Part III will then go on to address the limited Department of Justice (DOJ) guidance and case law pertaining to this technology. Part IV will discuss what appears to be a concerted effort by the US government to prevent the public disclosure of information about this technology. Part V will reveal, however, that the existence of the technology is both publicly known and acknowledged by governments in other countries. Part VI will describe how foreign governments and criminals can and do use cellular surveillance equipment to exploit the vulnerabilities in phone networks, putting the privacy and security of Americans’ communications at risk. Part VII will argue that the public is paying a high price for t e U g ve n ent’s pe pet t n f fictional secrecy surrounding cell phone interception technology. Specifically, such fictional claims of secrecy prevent policy makers from publicly addressing the threats to the security of cellular communications. Part VIII will argue that cellular network vulnerabilities should be addressed publicly in the larger cyber security policy process Congress is currently undertaking. Finally, Part IX will examine possible technical avenues through which solutions could come. II. AN INTRODUCTION TO CELL PHONE INTERCEPTION TECHNOLOGY Because cellular telephones send signals through the air, cellular communications are inherently vulnerable to interception by many more parties than communications carried over a copper wire or fiber optic cable into a home or business.29 This increased exposure to interception exists because anyone wishing

28 See L be ty nd ec ty n C ng ng W ld: Rep t nd Rec end t ns f t e P es dent’s Review Group on Intelligence and Communications Technologies 22 (2013), http://www.lawfareblog.com/wp-content/uploads/2013/12/Final-Report-RG.pdf (advising the US g ve n ent t “s pp [t] eff ts t enc ge t e g e te se f enc ypt n tec n l gy f d t n transit, at rest, in the cloud, and in storage.”). 29 See Craig Timberg and Ashkan Soltani, By cracking cellphone code, NSA has capacity for decoding private conversations, Washington Post, December 13, 2013, available at http://www.washingtonpost.com/business/technology/2013/12/13/e119b598-612f-11e3-bf45- 61f69f54fc5f_st y. t l (“Cellp ne c nve s t ns l ng ve been c e s e t nte cept t n

7

to tap a traditional wireline telephone call must physically access the network infrastructure transporting that call—such as by attaching interception equipment to the telephone w es ts de t e e f t e t get t t e telep ne c p ny’s central office.30 In contrast, intercepting a cellular telephone call only requires sufficient geographic proximity to the handset of one of the callers and the right kind of wireless interception equipment. Moreover, the distance from which cellular calls are vulnerable to interception can be increased with bigger antennas and high- powered radio equipment.31 Cellular telephone calls can, of course, be intercepted by government agencies with the assistance of the wireless carriers via government mandated interception capabilities these companies have built into their networks.32 In fact, the vast majority of surveillance performed by law enforcement agencies in the United States is, almost certainly, carrier-assisted surveillance.33 But cellular phone transmissions can also be captured without the assistance, or even the knowledge, of the carriers. The unmediated nature of this kind of interception, combined with

ones conducted on traditional telephones because the signals are broadcast through the air, making f e sy c llect n.”) 30 See id. Carrier assisted wiretaps once required that the interception take place near the target, such as at a call switching center. Today, telephone carriers have modern interception equipment that permits intercepts to be remotely initiated and controlled by a single dedicated surveillance team within the companies. See, for example, Utimaco Lawful Interception of Telecommunication Services (sales brochure), available at http://lims.utimaco.com/fileadmin/assets/brochures_datasheets_whitepapers/UTIMACO_LIMS_DA TASHEET_EN.pdf, (Utimac ’s L wf l Inte cept n M n ge ent yste “ s p ven s l t n f network operators and service providers to automate the administrative and operative tasks related to lawful interception. The system is based on a central management platform for the surveillance of communication services and implements electronic interfaces to various authorized law enforcement genc es nd t e n t ng… Key fe t es [ ncl de] Cent l d n st t n f nte cepts nd t get ss gn ents.”). See also Elaman government solutions, product brochure, https://www.wikileaks.org/spyfiles/files/0/188_201106-ISS-ELAMAN3.pdf t p ge 6 (“Lawful Interception provides access to calls and call-related information (telephone numbers, date, time, etc.) within telecommunications networks and delivers this data to a strategic Monitoring Center (MC)... Such an MC gives access to an entire country's telecommunications network from one central place, but it needs t e s pp t f pe t s...”). 31 As with cellular interception, WiFi signals can also be intercepted from a greater distance with the right equipment. See US National Security Agency, NIGHTSTAND - Wireless Exploitation/ Injection Tool, January 7, 2008, http://leaksource.files.wordpress.com/2013/12/nsa-ant- nightstand.jpg?w=604&h=781 ("Use of external amplifiers and antennas in both experimental and operational scenarios have resulted in successful NIGHTSTAND [WiFi] attacks from as far away as eight miles under ideal environmental conditions.") See also Xeni Jardin, DefCon WiFi shootout champions crowned: 125 miles, Boing Boing, July 31, 2005, http://boingboing.net/2005/07/31/defcon-wifi-shootout.html (describing a successful, record- setting 125 mile WiFi transmission by a team using 12 foot and 10 foot diameter satellite dishes). 32 See generally The Communications Assistance for Law Enforcement Act (CALEA), Pub. L. No. 103- 414, 108 Stat. 4279, codified at 47 U.S.C. §§ 1001-1010. 33 See Eric Lichtblau, Wireless Firms Are Flooded by Requests to Aid Surveillance, New York Times, July 8, 2012, available at http://www.nytimes.com/2012/07/09/us/cell-carriers-see-uptick-in- requests-to-aid-surveillance.html (describing the 1.3 million requests the wireless carriers received in 2011 from law enforcement agencies).

8

the growing ease of access to cellular surveillance technology, makes the universe of private parties that can intercept a cellular call inestimably larger, and the range of their motives correspondingly broader, than the pool of potential law enforcement and national security actors who have both the legal capacity and technical capability to initiate a traditional wiretap of a wireline phone. The technologies that enable the direct interception of cellular phone calls without the assistance of a wireless carrier generally fall into two categories: passive and active.34 The former merely intercepts the signals sent between nearby phones and t e w eless p v de s’ network, while the latter transmits data to, and directly interacts with, the cellular phones under surveillance. Passive interception technology functions in two stages. First, the signals transmitted between a cellular phone and the wireless carrier’s netw k are intercepted as they are transmitted over the air. This process does not disrupt the signals in transit. Second, once intercepted, if the communications are encrypted, they must be must be decrypted for analysis.35 Not all communications are encrypted in transmission but, if they are, the ease of decryption varies based on the strength of the encryption algorithm chosen by the wireless carrier.36 As described in greater detail in Part V of this Article, t e j “G M” netw k pe t s n t e US, such as AT&T and T-Mobile, still use extremely weak encryption algorithms for t e lde “2G” netw ks w c can be easily deciphered with widely available

34 See Karsten Nohl and Chris Paget, GSM — SRSLY ?, 26th Chaos Communication Congress (26C3), December 27, 2009, page 11, http://events.ccc.de/congress/2009/Fahrplan/attachments/1519_26C3.Karsten.Nohl.GSM.pdf. 35 Encrypted cellular communications must be decrypted before they can be listened to, at least when encryption is used. In some countries, like India, encryption between phones and the network base stations is disabled. In India, this is a result of legislation prohibiting the use of encryption, likely intended to make interception by the government easier. See Pranesh Prakash, How Surveillance Works in India, New York Times India Ink blog, July 10, 2013, available at http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in- nd / (“p v de s n Ind have been known use A5/0, t t s, n enc ypt n”). ee also Nehaluddin Ahmad, Restrictions on cryptography in India – a case study of encryption and privacy, Computer Law & Security Review, Volume 25, issue 2, pp173- 180, 2009. In the United States, there is no law requiring the carriers to use encryption to protect calls. The choice is left entirely up to the wireless carriers, who do use encryption in some cases, but not always. See supra Part V. 36 A number of encryption algorithms are supported by modern cellular telephone systems, but the spec f c lg t sed t enc ypt c n c t ns between telep ne nd t e c e s’ netw k s c sen by t e w eless c e . In t e Un ted t tes, t e A5/1 lg t nd A5/0 (t e “NULL” encryption option) are still used by the major GSM carriers, AT&T and T-Mobile for their 2G networks. See supra Part V. The major CDMA carriers, Sprint and Verizon, use different encryption algorithms for their 2G and 3G networks. The Long Term Evolution (LTE) 4G cellular standard, which is the next generation technology adopted by all US carriers, includes support for encryption algorithms that are much stronger. However, as with prior generations of cellular technology, w eless c e s c n st ll c se t n t se ny enc ypt n (t e “NULL” pt n) w th LTE. See http://business.verizonwireless.com/content/dam/b2b/resources/LTE_FutureMobileTech_WP.pdf (“T e 128-b t AE lg t s t e p efe ed pt n n t e Ve z n W eless 4G LTE netw k… AE s preferred because it has undergone more public scrutiny t n t e enc ypt n pt ns.”).

9

software or purpose-built hardware.37 Moreover, although the competing “CDMA” cellular networks (operated by Verizon and Sprint) use different, incompatible cellular technology and encryption algorithms, surveillance companies offers products capable of intercepting and tracking CDMA phones too.38 Active interception, performed with a device known as an IMSI catcher or cell site simulator, works by impersonating a wireless base station—the carrier owned equipment installed at a cell tower to which cellular phones connect—and tricking t e t get’s phone into connecting to it.39 For some surveillance capabilities, such as intercepting communications content, the IMSI catcher can also impersonate the c e ’s network infrastructure, such that calls and text messages are transmitted through the IMSI catcher, once again without disrupting the communication and thus remaining imperceptible to the target.40 Depending on the particular features of the surveillance device and how they are configured by the operator, IMSI catchers can be used to identify nearby phones,41 to locate them with extraordinary

37 See supra Part V for a discussion of the software tools and commercial products now available to crack cellular encryption algorithms. 38 These include the Harris Corporation, and Elaman. See Lin Vinson, Major Account Manager, Wireless Products Group, Harris Corporation, letter to Raul Perez, City of Miami Police Department, August 25, 2008, http://egov.ci.miami.fl.us/Legistarweb/Attachments/48003.pdf t p ge 2 (“The Harris StingRay and KingFish systems are compatible with the CDMA standard...”). See Harris StingRay product sheet, http://files.cloudprivacy.net/Harris_Stingray_product_sheet.pdf at 1 (Desc b ng ne ve s n f t e H s t ngR y s “Transportable CDMA Interrogation, Tracking and Location, and Signal Collection Inf t n C llect n yste ”). See also Elaman government solutions, product brochure, https://www.wikileaks.org/spyfiles/files/0/188_201106-ISS- ELAMAN3.pdf t p ge 14 (“For operational field usage, off-air GSM monitoring systems are very powerful and essential....Systems for ... CDMA e [ ls ] v l ble.”). See http://en.intercept.ws/catalog/2197.html and http://www.ewa- gsi.com/Fact%20Sheets/Arrow%20CDMA%20Fact%20Sheet.pdf. 39 See Daehyun Strobel. IMSI Catcher, Seminar Work, Ruhr-Universitat Bochum, 2007, ttp://www.e sec. b.de/ ed /c ypt / tt c ents/f les/2011/04/ s _c tc e .pdf t 17 (“An IMSI Catcher exploits [the lack of authentication in GSM] weakness and masquerades to a Mobile [P ne] s B se t t n.”) 40 Ability Limited (Hong Kong), In-Between Interception System, Product Description, at page 4, ttp://www.t pl nkp c.c /pdf/IBI _B c e.PDF (“It s t e M n-In-The-Middle (MitM) attack n G M c n c t n w c s f lly ple ented n t e IBI ….D ng t e eg st t n nd authentication process compact BTS requests mobile phones to implement encryption A5/2 which they do. Real-time A5/2 decipher decrypts the information exchange and calculates Kc (ciphering Key). F t s ent IBI c n f lly t te t get’s p ne nd t lks w t GSM network on its behalf. So the target communicates with compact BTS which poses to be a real GSM network. The real GSM network talks to clone of the target phone. Computer collects information from the compact BTS and the clone. Such a scheme makes possible interception of incoming and outgoing calls.”) (e p s s added). 41 Cellxion, UGX Series 330, Transportable Dual GSM/ Triple UMTS Firewall and Analysis Tool, page 7 http:// s3.documentcloud.org/documents/810703/202-cellxion-product-list-ugx-optima- platf .pdf (“C p e ens ve dent f c t n f IM I, IMEI, nd TM nf t n ... s lt ne s g speed cq s t n f ndsets ( p t 1500 pe n te), c ss p t f ve netw ks.”). See also Septier IM I C tc e , ttp://www.sept e .c /146. t l (“ ept e IMSI Catcher allows its user to extract the IM I nd IMEI f G M M pe t ng n ts c ve ge e ”)

10

precision,42 to intercept outgoing calls and text messages,43 as well as to block service, either to all devices in the area, or to particular devices.44 Cellular interception technology, by its very nature, tends to be invasive and overbroad in its collection of data.45 Active interception devices send signals, often indiscriminately, through the walls of homes,46 vehicles, purses and pockets in order to probe and identify the phones located inside.47 Both active and passive devices also pick up the signals of other phones used by innocent third parties, particularly when government agencies using them do not know the exact location of their target and thus must drive through cities and neighborhoods while deploying cellular interception equipment in order to locate her. Both passive and active telephone surveillance technologies exploit security flaws in cellular telephones. Passive devices exploit the weak or, in some cases, lack of any encryption used to protect calls, text messages and data transmitted between

42 See Anchorage Police Department, Memorandum, Sole Source Proprietary Purchase Request Harris KingFish Dual Mode System, June 24, 2009, http://files.cloudprivacy.net/anchorage-pd-harris- memo.pdf ("The system allows law enforcement agencies ... the ability to ... Identify location of an ct ve cell l dev ce t w t n 25 feet f ct l l c t n nyw e e n t e Un ted t tes”) See also Harris AmberJack product sheet, http://egov.ci.miami.fl.us/Legistarweb/Attachments/34769.pdf at 2 (“A be J ck s p sed y d ect n-finding (DF) antenna system capable of tracking and locating mobile phone users. The DF antenna array is designed to operate with Harris' Loggerhead nd t ngR y p d cts.”) See also “G M Cell l M n t ng yste s” b c e by PKI Elect n c Intell gence G bH t 12 (dev ce c n “l c t[e]... t get b le p ne w t n n cc cy f 2 [ete s]”), v l ble t http://www.docstoc.com/docs/99662489/GSM-CELLULAR-MONITORING-SYSTEMS---PKI- Electronic-#. 43 See Ability (infra fn 36)(noting the ability to intercept “ nc ng nd tg ng c lls”); See also Verint Sales Brouchure, 2013, http://s3.documentcloud.org/documents/885760/1278-verint- product-list-engage-gi2-engage-pi2.pdf t 15 (“Listen to, read, edit and reroute incoming and outgoing calls and text messages”). 44 See CellX n, UGX Opt Pl tf , nf (fn 37) t p ge 2 (“Gl b l Den l f e v ce: D s ble ll handsets except operationally friendly”) See also See Anchorage Police Department, Memorandum, Sole Source Proprietary Purchase Request Harris KingFish Dual Mode System, June 24, 2009, http://files.cloudprivacy.net/anchorage-pd-harris-memo.pdf ("The system allows law enforcement agencies ... the ability to ... Interrupt service to active cellular connection ... Prevent connection to dent f ed cell l dev ce”) 45 In some cases, this may be a selling point. See Verint Sales Brouchure, 2013, http://s3.documentcloud.org/documents/885760/1278-verint-product-list-engage-gi2-engage- pi2.pdf t 7 (“c llect ss G M t ff c ve w de e ”). 46 T e dev ces send s gn ls l ke t se e tted by c e ’s wn b se st t ns. T se s gn ls, f c se, “penet te w lls” (necess ly, t p v de c nnect v ty indoors). What You Need to Know About Your Network, AT&T, http://www.att.com/gen/press-room?pid=14003; see also E.H. Walker, Penetration of Radio Signals Into Buildings in the Cellular Radio Environment, 62 THE BELL SYSTEMS TECHNICAL JOURNAL 2719 (1983), available at http://www.alcatel- lucent.com/bstj/vol62-1983/articles/bstj62-9-2719.pdf. 47 See John Kelly, Cellphone data spying: It's not just the NSA, USA Today, December 8, 2013, available at http://www.usatoday.com/story/news/nation/2013/12/08/cellphone-data-spying-nsa- p l ce/3902809/ (“Typ c lly sed t nt s ngle p ne's l c t n, t e syste nte cepts d t f ll p nes w t n le, f t e , depend ng n te n nd ntenn s.”)

11

phones and the w eless c e s’ base stations. Active surveillance devices, on the other hand, exploit the lack of authentication of the base station by cellular phones.48 As a result, phones have no way to differentiate between a legitimate base st t n wned pe ted by t e t get’s w eless c e nd g e device impersonating a carrier’s base station.49 Passive wireless surveillance devices do not transmit any signals.50 These devices are thus far more covert in operation—indeed effectively invisible51—but they can only detect signals of nearby phones when those phones are actually transmitting data.52 Active surveillance devices have the disadvantage of being relatively less covert because they produce tell-tale signals that are detectable using sophisticated, counter-surveillance equipment,53 but they possess a corresponding advantage in that they can rapidly identify and locate all nearby phones that are turned on, even if they are not transmitting any data.54

48 See Strobel infra n te ** t 17 (“An IM I C tc e expl ts [the one sided authentication] weakness [ n G M] nd sq e des t M b le t t n s B se t t n”). 49 More recent cellular phone systems, including so-called 3G and 4G networks, now include the capability for phones to authenticate the network base stations. See generally Muxiang Zhang; Yuguang Fang, Security analysis and enhancements of 3GPP authentication and key agreement protocol, Wireless Communications, IEEE Transactions on, vol.4, no.2, pp.734,742, March 2005, available at http://islab.iecs.fcu.edu.tw/GroupMeeting/PowerPoint/20050506_1.pdf. However, even the latest smartphones are backward compatible with older, vulnerable phone network technologies, which allows the phone to function if it is taken to a rural location or foreign country where the only service offered is 2G. As a result, modern phones remain vulnerable to active surveillance via a protocol rollback attack in which the nearby 3G and 4G network signals are first jammed. See Matthew Green, On cellular encryption, A Few Thoughts on Cryptographic Engineering, May 13, 2013, http://blog.cryptographyengineering.com/2013/05/a-few-thoughts-on-cellular- enc ypt n. t l (“T e b ggest s ce f c nce n f 3G/LTE s t t y y n t be s ng t. M st phones are programmed to gracefully 'fail over' to GSM when a 3G/4G connection seems unavailable. Active attackers exploit this feature to implement a rollback attack — jamming 3G/4G connections, and thus re- ct v t ng ll f t e G M tt cks.”). 50 See Ability, GTReS – GSM Traffic Recording System, http://www.interceptors.com/intercept- solutions/Passive-GSM-Inte cept . t l (“GTRe s lt -band fully passive GSM interception system designed to record the entire traffic occurring between Base Transmitting Stations (BTS) and Mobile Stations (MS) located w t n t e syste ’s pe t n l nge. T s e ns l te lly tens even nd eds f s lt ne s c lls…. GTRe d es n t ve ny t ns tt ng p ts… GTRe ’ pe t n s c pletely ndetect ble.”) 51 See Verint Sales Brouchure, 2013, http://s3.documentcloud.org/documents/885760/1278-verint- product-list-engage-gi2-engage-pi2.pdf t 7 (“Operate undetected leaving no electromagnetic signature”). 52 Any phone that is connected to a cellular network will regularly transmit data to nearby base stations, even if it is not making calls, sending text messages or using the Internet. Locating a phone that is not currently transmitting data with a passive interception device may, however, require w t ng s e t e nt l t e dev ce “c ecks n” w t t e cell l netw k r otherwise engages in a communication with a nearby base station. 53 T ese dev ces e kn wn s “IM I c tc e c tc e s”. See CatcherCatcher, Security Research Labs, https://opensource.srlabs.de/projects/mobile-network-assessment-tools/wiki/CatcherCatcher, (“T e C tc e C tc e t l detects b le netw k eg l t es nt ng t f ke b se st t n ct v ty…F IM I c tc e s t c eve t e g ls t ey w ll need t s w be v d ffe ent f n l b se st t ns”). 54 See Cellxion, supra note 38.

12

A. AN APPROXIMATE HISTORY OF CELLULAR PHONE INTERCEPTION TECHNOLOGY55 Rohde & Schwarz, a German manufacturer of radio equipment, is generally believed to have created the first purpose-built active device capable of performing surveillance on cellular telephones.56 Their first model, introduced in 1996, identified nearby wireless telephones by forcing them to transmit their serial number, or International Mobile Subscriber Identity (IMSI).57 Within a year, the company had introduced a more sophisticated product that could also intercept outgoing phone calls.58 US government agencies have used both active and passive forms of cellular telephone surveillance technology since at least the early 1990s, if not earlier.59 Military and intelligence agencies were early adopters of this technology, with law enforcement agencies quickly following their lead.60 Passive devices, often referred to as digital analyzers, were used by law enforcement agencies as early as 1991.61 Active surveillance devices were also used by federal law enforcement agencies as early as 1995.62 Initially, US agencies used devices that were “general use” cell site

55 As telephone interception technology is also used by intelligence agencies and the military, it is impossible to tell a totally accurate history of the development of wireless telephone interception technology. As with many surveillance technologies, the military and intelligence community are the first to use them, and after time, they trickle down to law enforcement. Neither the manufacturers of this equipment nor their many intelligence and military clients advertise their use. This portion of our article is an attempt to paint an approximate picture, but it is quite likely that there are many aspects to this story that are missing, due to the fact that they remain classified. 56 The earliest public document describing IMSI catchers and the Rohde & Schwarz products is an article in 1997 by Dirk Fox, a German security consultant. See Dirk Fox, IMSI-Catcher, Datenschutz und Datensicherheit, 21:539–539, 1997, available at http://www.secorvo.de/publikationen/imsi- catcher-fox-1997.pdf (in German). Five years later, Fox published an updated, more in-depth article about the same technology. See Der IMSI-Catcher, Datenschutz und Datensicherheit, 26:212–215, 2002, http://www.secorvo.de/publikationen/imsicatcher-fox-2002.pdf (also in German). 57 See Strobel infra note ** at 17. See also, MMI Research Ltd v Cellxion Ltd & Ors [2009] EWHC 418 (Pat) (11 March 2009), http://www.bailii.org/ew/cases/EWHC/Patents/2009/418.html (describing a presentation of the Rohde & Schwarz GA-090 IMSI Catcher device to three German wireless carriers in December 1996.) 58 See Strobel infra note ** at 17. 59 As US law enforcement and intelligence agencies do not advertise their intelligence gathering sources and methods, there is no way to accurately determine when US government agencies first started to use active or passive wireless phone surveillance technology. 60 See John Kelly, Cellphone data spying: It's not just the NSA, USA Today, December 8, 2013, available at http://www.usatoday.com/story/news/nation/2013/12/08/cellphone-data-spying-nsa- p l ce/3902809/ (“In t lly devel ped f l t y nd spy genc es, t e t ng ys e n g ded sec et by l w enf ce ent nd t e n f ct e , H s C p. f Melb ne, Fl .”) 61 See Glen L. Roberts, Who's On The Line? Cellular Phone Interception at its Best, Full Disclosure, issue 24, 1991, archived at http://blockyourid.com/~gbpprorg/2600/harris.txt (describing the marketing by the Harris Corporation of TriggerFish passive surveillance devices to law enforcement agencies at the National Technical Investigators Association conference in 1991). 62 See Tsutomu Shimomura, Catching Kevin, Wired, Issue 4.02, February 1996, available at http://www.wired.com/wired/archive/4.02/catching_pr.html

13

simulators, which wireless carrier technicians operated to test cellular phones.63 Later, cellular equipment manufacturers created and sold cell site simulators specifically designed for government surveillance. Infamous computer hacker Kevin Mitnick was located in 1995 by FBI agents using a combination of an active cell-site simulator and a passive TriggerFish, the brand name of a digital analyzer manufactured by the Harris Corporation.64 The active cell s te s l t w s ble t p ge M tn ck’s p ne without causing an audible ring,65 after which the passive TriggerFish was used to locate the phone.66 By 2003,67 Harris had introduced its more sophisticated StingRay product, which performed active surveillance of digital cellular telephones.68 The company now manufactures an extensive range of cellular telephone surveillance products,69 which can be mounted in vehicles, on airplanes and drones, or carried by a person.70 Harris sells its products to local, state and federal law enforcement agencies,71 intelligence agencies, and the military.72 The company dominates the US law

63 Id. 64 Id. 65 Id. This capability is commonly efe ed t s “s lent M ”. See generally Fabien Soyez, Getting the Message? Police Track Phones with Silent SMS, Owni, January 27, 2012, available at http://owni.eu/2012/01/27/silent-sms-germany-france-surveillance-deveryware. 66 Shimomura, supra note **. 67 US Trademark office registration of StingRay, 8/21/2001, registration # 2762468, describing a “ lt -channel, software-defined, two-way electronic surveillance radios for authorized law enforcement and government agencies for interrogating, locating, tracking and gathering information f cell l telep nes.” F st Use In C e ce: 20030302. 68 See Harris StingRay product sheet, http://files.cloudprivacy.net/Harris_Stingray_product_sheet.pdf t 1 (“ t ngR y s H s' l test ffe ng n l ng l ne of advanced wireless surveillance products. StingRay is a multichannel software defined radio that performs network base station surveys, Dialed Number and registration collection, mobile interrogation, and target tracking and location with Harris' AmberJack Direction-F nd ng Antenn .”). 69 See generally Ryan Gallagher, Meet the machines that steal your phone’s data, Ars Technica, September 25, 2013, http://arstechnica.com/tech-policy/2013/09/meet-the-machines-that-steal- your-phones-data/. 70 See Jennifer Valentino-DeVries, Judge Questions Tools That Grab Cellphone Data on Innocent People, The Wall Street Journal, October 22, 2012, http://blogs.wsj.com/digits/2012/10/22/judge- questions-tools-that-grab-cellphone-data-on-innocent-pe ple/ (“ t ng y eq p ent can be carried by nd nted n ve cles even d nes.”) See also Freedom of Information Act response from US Immigrations and Customs Enforcement to Christopher Soghoian, September 19, 2012, at 44, available at https://www.documentcloud.org/documents/479397- st ng yf . t l#d c ent/p44/ 14 (desc b ng t e p c se f “ t ng y II A b ne T n ng” sess n nd n “A b ne Fl g t K t”) 71 See John Kelly, Cellphone data spying: It's not just the NSA, USA Today, December 8, 2013, available at http://www.usatoday.com/story/news/nation/2013/12/08/cellphone-data-spying-nsa- p l ce/3902809/ (“At le st 25 p l ce dep t ents wn t ng y, s tc se-size device that costs as c s $400,000 nd cts s f ke cell t we ….In s e st tes, t e dev ces e available to any local police department via state surveillance units. The federal government funds most of the purchases, via anti-te g nts.”) 72 See US Marine Corps, Intelligence Training Enhancement Program, Course Program for SET017, https://www.mcis.usmc.mil/ITEP/Lists/ITEP%20Course%20Catalogue/DispForm.aspx?ID=31

14

enforcement market, although several other companies also sell similar technology to US military and intelligence agencies.73 B. USES OF DIRECT INTERCEPTION TECHNOLOGY Law enforcement agencies perform most interception with the assistance of telecommunications and Internet companies using carrier-owned equipment or technology that enables surveillance—typically with the aid of dedicated electronic surveillance and compliance teams employed by these companies.74 For more than

( ncl des “H s C p t n: G ss e , L ng p, Bl ckF n, Bl ckF n II, H wksB ll, p D g, FishFinder, KingFish, StingRay, StingRay II, GSM Interrogator, CDMA Interrogator, iDEN Interrogator, UMTS Interrogator, FishHawk, Porpoise, FireFish, Tarpon, AmberJack, Harpoon, Moray, LanternEye, R yF s , t neC b”). See also NOTICE OF INTENT TO AWARD A SOLE SOURCE CONTRACT-HARRIS: KINGFISH DUAL MODE SYSTEM, U.S. Army Intelligence and Security Command, January 12, 2009, available at https://www.fbo.gov/index?s=opportunity&mode=form&id=fd03ebae781f3a3fdb7633699bc1e351 &tab=core&_cview=1. See also Interrogation, Tracking, Location and Signal Information Collection System Devices with Software and Training, United States Marine Corp, September 12, 2006, available at https://www.fbo.gov/index?s=opportunity&mode=form&id=6a5efbcce2b7bdf2f37448ad68d48e7e &tab=core&_cview=0, Harris Corp Blackfin Equipment, Space and Naval Warfare Systems Command, May 24, 2010, available at https://www.fbo.gov/index?s=opportunity&mode=form&tab=core&id=f34fc14f76e8744bfe75d41e 6d0242db. See also, U.S. Special Operations Command (Naval Special Warfare Group 1), Fishhawk Software, September 22, 2011, https://www.fbo.gov/index?s=opportunity&mode=form&tab=core&id=3176fb4a66f92793ac34e76 70205e2c5 ((“ t ngR y II - Special Equipment- Over-The-Air special signal software that is c p t ble w t t e H s t ngR y II yste .”) 73 Other manufacturers of cellular surveillance technology used by the US military and intelligence agencies include Boeing, Cellxion, and Martone Radio Technology. See Audrey L. Allison and Bruce A. Olcott, Comments of the Boeing Company, Technical Approaches to Preventing Contraband Cell Phone Use in Prisons, Docket No. 100504212-0212-01, Before the United States Department of Commerce, National Telecommunications and Information Administration, June 11, 2012, available at http://www.ntia.doc.gov/files/ntia/comments/100504212-0212- 01/attachments/Boeing%20and%20DRT%20Comments%20on%20NTIA%20Contraband%20Cell% 20P ne%20NOI%206%2011%2010.pdf, (“DRT n f ct es l ne f w eless l c t n nd management technologies that emulate a base station to detect and locate wireless handsets of interest in a limited geographic are .”). See also Darrell J. Patterson, Phoenix Global Support, Application for New or Modified Radio Station Under Part 5 of FCC Rules – Experimental Radio Service, Federal Communications Commission, March 21, 2011, available at https://apps.fcc.gov/oetcf/els/reports/442_Print.cfm?mode=current&application_seq=47486&licen se_seq=48001 (requesting a license to use transmitting devices made by Martone Radio Technology, Harris and Cellxion). Phoenix Global Support, the company that requested FCC that license, is located less than 15 miles from Fort Bragg, in Fayetteville, NC, the headquarters of the Joint Special Ope t ns C nd (J OC). T e c p ny’s webs te st tes t t t ffe s “c plete cl sses nd curriculum for Signals Intelligence (SIGINT) and Electronic Warfare (E/W) spanning the spectrum of w eless c n c t ns.” See Phoenix Global Support, www.pgsup.com. 74 See William B. Petersen, General Counsel, Verizon Wireless, Letter to Edward J. Markey, Congressman, May 22, 2012, available at http://web.archive.org/web/20121217111531/http://markey.house.gov/sites/markey.house.gov/f iles/documents/Verizon%20Wireless%20Response%20to%20Rep.%20Markey.pdf , Page 3 (“Ve z n W eless s ded c ted te f pp x tely seventy t t w ks . . . t esp nd t l wf l

15

one hundred years, the telephone companies have provided such assistance.75 While carrier performed or enabled surveillance is generally the easiest, most efficient and covert way to intercept communications, it is not the only way.76 In spite of the user-friendly, often inexpensive, surveillance capabilities provided to the government by the wireless carriers,77 there are certain situations where governments may need or prefer to engage in direct, unmediated surveillance of telephones themselves using an active or passive device. These include: (1) Identifying unknown phones currently used by a known target. In situations where a surveillance target is believed to frequently switch phones (for example, by using so-called “b ne ” d sp s ble p nes),78 investigators may wish to learn the serial number of the phone currently in use, which is necessary in order to initiate a carrier-assisted wiretap79 or Pen Register/ Trap and Trace device (hereinafter Pen/Trap).80 Law enforcement can determine the specific phone used de nds f c st e nf t n.”). See also Timothy P. McKone, Executive Vice President, Federal Relations, AT&T, Letter to Edward J. Markey, Congressman, May 29, 2012, available at http://web.archive.org/web/20121228183409/http://markey.house.gov/sites/markey.house.gov/f les/d c ents/AT%26T%20Resp nse%20t %20Rep.%20M key.pdf, p ge 2 (“AT&T e pl ys more than 100 full time workers . . . for the purpose of meeting law enforcement demands.) 75 By 1895, the police in New York had the ability to wiretap any telephone in the city. See Wes Oliver, Wiretapping and the Apex of Police Discretion, Widener Law School Legal Studies Research Paper No. 10-14, April 22, 2010, available at ttp://p pe s.ss n.c /s l3/p pe s.cf ? bst ct_ d=1594282 (“In t e e ly ye s f p lice wiretapping, a police officer would simply go to the telephone company and request that the phone c p ny ss st t e w t w et p… F [ n ff ce n l we M n tt n], e be s f t e s x-man wiretap squad could listen-in on any telephone call in the C ty f New Y k”). 76 In fact, since the earliest days of the telephone, the police have directly performed wiretaps too. See Meyer Berger, Tapping the Wires, New Yorker, June 18, 1938, at 41, available at http://www.spybusters.com/History_1938_Tapping_W es. t l (“In t se d ys p l ce w e-tappers j st w lked nt t e Telep ne C p ny’s ff ces, sked f t e l c t n f t e w es t ey we e interested in, and got the information without fuss. Lines were usually tapped right in the cellar of the house or t n ts de w ll b x”). 77 See Christopher Soghoian, ACLU docs reveal real-time cell phone location spying is easy and cheap, Slight Paranoia blog, April 3, 2012, available at http://paranoia.dubfire.net/2012/04/aclu-docs- reveal-real-time-cell-phone.html (quoting Paul Taylor, Electronic Surveillance Manager, Sprint Nextel, st t ng: “[O web b sed GP t ck ng t l] s j st e lly c g t n f e w t l w enf ce ent. T ey ls l ve t t t s ext e ely nexpens ve t pe te nd e sy”). 78 See The Wire: Amsterdam, t 00:42:23 (HBO telev s n b dc st Oct. 10, 2004) (“T ey ke couple of calls with a burner, throw it away. Go on to the next phone, do the same. There's more of t se t ngs l y ng nd t e st eets f West B lt e t n e pty v ls.” “Well, how the fuck you s pp sed t get w e p n t t?” “Ye , well, f st t w s p yp ne nd p ge s. T en t w s cell phones and face-to-face meets. Now this. The motherfuckers do learn. Every time we come at them, t ey le n nd dj st.”). 79 See 18 U.S.C. §§ 2511–2520 (2012) (authorizing the interception of wire, oral or electronic communications—including communications content—by law enforcement to investigate crimes enumerated in the statute upon satisfying various elements set out in the statute). 80 See 18 U.S.C. §§ 3121–3127 (2012) (authorizing law enforcement to install and use a pen register dev ce t “ ec [d] dec d[e] . . . [n n-content] dialing, routing, addressing, or signaling information . . . transmitted by an instrument or facility for which a wire or electronic communication is t ns tted [ ] p v ded ” nd t nst ll nd se t p nd t ce dev ce t “c pt [e] t e nc ng

16

by a particular surveillance target by deploying an IMSI catcher to collect data about ne by p nes t lt ple l c t ns, s c s t e t get’s e nd pl ce f b s ness, ultimately narrowing the search to only those phones that were present in all of the monitored locations.81 (2) Locating devices that cannot be found by the wireless carriers. Federal E- 911 regulations require that the carriers be able accurately to determine the location of cellular phones.82 As this technical obligation was mandated in the context of E-911,83 it only applies to devices capable of making a telephone call to 911. As such, there is no affirmative obligation that wireless carriers be able to accurately locate data-only devices, such as tablet computers and mobile data-cards. In cases where the government wishes to locate data-only devices that cannot be accurately located by the wireless carrier,84 they are likely to turn to active cellular interception. (3) Selectively blocking devices or dialed numbers. There are situations and environments where public safety officials may use a cell site simulator to selectively block the use of particular phones.85 Some prisons, for example, have

electronic or other impulses which identify the originating number or other dialing, routing, addressing, and signaling information reasonably likely to identify the source of a wire or electronic communication, provided, however, that such information shall not include the contents of any c n c t n”). 81 See United States v. Arguijo et al (Criminal Complaint), February 13, 2012, at 8, n.1 available at ttp://www.j st ce.g v/ s / ln/p /c c g /2013/p 0222_01d.pdf (“L w enf ce ent ff ce s f l w t C p ’s ppe nce, v ng p ev sly v ewed p t g p s f nd bse ved him during prior surveillance, used a digital analyzer device on three occasions in three different locations where Chaparro was observed to determine the IMSI associated with any cellular telephone being carried by Chaparro. Using the digital analyzer device, in conjunction with surveillance of C p , l w enf ce ent dete ned t t t e telep ne … w s n t e s e v c n ty n t e t ee sep te l c t ns w e e C p w s bse ved.”) 82 See 47 CFR 20.18(h). 83 Although the requirement that wireless carriers have the capability to locate handsets was mandated for purposes of locating cell phone subscribers making emergency calls (a situation in which the caller would presumably wish for her location to be known to the authorities), once the wireless carriers implemented this technical capability, law enforcement appropriated the resource to enable the tracking of targets through geo-location data, all without the knowledge of handset owners. 84 The FCC gave wireless carriers the choice of using handset-based or network-based technology to comply with the E-911 mandate. The handset-based solution involves the installation in telephone handsets of GPS chips that can be remotely queried. In contrast, the network-based solution requires the installation of specialized technology at the ca e s’ b se st t ns, w c c n t en l c te ny dev ce c nnected t t e c e ’s netw k, ncl d ng d t -cards and tablet computers. As such, carriers such as AT&T and T-Mobile, which have deployed network-based E-911 technology, are able to locate data-devices, while Verizon and Sprint, which deployed handset-based E-911 technology, cannot. See generally FCC Third report and Order, CC Docket No. 94-102, October 6, 1999, available at http://transition.fcc.gov/Bureaus/Wireless/Orders/1999/fcc99245.pdf. 85 See Anchorage Police Department, Memorandum, Sole Source Proprietary Purchase Request Harris KingFish Dual Mode System, June 24, 2009, http://files.cloudprivacy.net/anchorage-pd-harris- e .pdf (“T e K ngF s D l-Mode System ... is a Harris Government Communications System Division proprietary designed cellular phone surveillance and tracking system.... This system allows

17

installed devices that permit access to registered phones, such as those used by guards and other staff, while blocking all unregistered phones, such as those smuggled in to the facility, from making or receiving calls.86 Law enforcement agencies may also, during high-security events like a hostage situation or a bomb threat, seek to redirect outgoing numbers dialed by particular phones or block incoming calls to all nearby phones. (4) Foreign intelligence and military operations. Although US government agencies can compel surveillance assistance from US wireless carriers, this power does not extend to telephone companies in foreign countries. Moreover, even if some level of assistance is available from foreign governments, US agencies may wish to keep their foreign surveillance activities covert, such as when the surveillance is aimed at that foreign government and its political leaders.87 As a result, when conducting surveillance abroad—and in some cases, even domestically88—direct surveillance technology may be the most effective surveillance (or even the only) tool available to US intelligence agencies and military units for intercepting certain communications or tracking particular phones.89 The

law enforcement agencies ... to ...Interrupt service to active cellular connection. Prevent connection to identified cellular device ('No Service').”). 86 See National Telecommunications and Information Administration, US Department of Commerce, Report on Contraband Cell Phones In Prisons, Possible Wireless Technology Solutions, December 2010, pages 19-25, http://www.ntia.doc.gov/files/ntia/publications/contrabandcellphonereport_december2010.pdf (desc b ng “ n ged ccess” et ds f p event ng c nt b nd cell p nes f be ng sed n prisons). 87 See How NSA Spied on Merkel Cell Phone from Berlin Embassy, Der Spiegel, October 27, 2013, http://www.spiegel.de/international/germany/cover-story-how-nsa-spied-on-merkel-cell-phone- from-berlin-embassy-a-930205. t l (“F t e f f t e e b ssy, spec l n t f t e CIA nd NSA can apparently monitor a large part of cellphone communication in the government quarter. And there is evidence that agents based at Pariser Platz recently targeted the cellphone that [German C ncell Angel ] Me kel ses t e st.”). See also Duncan Campbell, Cahal Milmo, Kim Sengupta, Nigel Morris, and Tony Patterson, Revealed: Britain's 'secret listening post in the heart of Berlin,' The Independent, November 5, 2013, http://www.independent.co.uk/news/uk/home-news/revealed- britains-secret-listening-post-in-the-heart-of-berlin-8921548.html. 88 When performing surveillance on sophisticated targets with counter-intelligence expertise, such as foreign embassies and foreign intelligence services operating from foreign embassies in the US, US intelligence agents are likely to use passive cellular interception technology, because it is far more difficult to detect. See Matthew M. Aid, Spy Copters, Lasers, and Break-In Teams, Foreign Policy, November 19, 2013, http://www.foreignpolicy.com/articles/2013/11/19/spy_copters_lasers_and_break_in_teams_fbi_sp ies_on_diplomats (“The FBI not only endeavors to steal or covertly compromise foreign government, military, and commercial computer, telecommunications, and encryption systems being used in the United States, but the FBI and NSA work closely to intercept the communications of all diplomatic missions and international organizations located on American soil…The FBI also uses a wide range of vehicles and airborne surveillance assets to monitor the movements and activities of foreign diplomats and intelligence operatives in Washington and New York. Some of the vans, aircraft, and helicopters used by the FBI for this purpose are equipped with equipment capable of intercepting cell- phone calls and other electronic forms of communication.”) (e p s s dded). 89 See Jeremy Scahill and Glenn Greenw ld, T e N A’s ec et R le n t e U. . Ass ss n t n P g , The Intercept, February 10, 2014, https://firstlook.org/theintercept/article/2014/02/10/the-nsas-

18

same logic, of course, applies to foreign governments conducting espionage in the United States.90 III. “KNOWN KNOWNS”—CASE LAW AND DOJ GUIDANCE US law enforcement agencies have used cellular interception technology for more than two decades91 and spent tens of millions of dollars acquiring these devices at federal, state and local levels.92 Notwithstanding this history, there is scant case law addressing its use in investigations. Indeed, when compared with traditional, carrier-assisted cellular phone tracking,93 there is limited case law and publically available internal agency guidance describing: (1) statutory authorities that may permit or preclude law enforcement use and how the Department of Justice (DOJ) interprets such authorities to permit or limit law enforcement use (to include any

secret- le/ (“[T] e N A d esn’t j st l c te t e cell p nes f te s spects by nte cept ng communications from cell phone towers and Internet service providers. The agency also equips d nes nd t e c ft w t dev ces kn wn s ‘v t l b se-t we t nsce ve s’ – creating, in effect, a fake cell phone tower that can force a targeted person’s dev ce t l ck nt t e N A’s ece ve without their knowledge. That, in turn, allows the military to track the cell phone to within 30 feet of its actual location, feeding the real-time data to teams of drone operators who conduct missile strikes or facilitate night raids. The NSA geolocation system used by JSOC is known by the code name GILGAMESH. Under the program, a specially constructed device is attached to the drone. As the drone circles, the device locates the SIM card or handset that the military bel eves s sed by t e t get.”) 90 See infra Part VI, discussing surveillance by foreign governments in the United States. 91 See supra **, discussing the fact that law enforcement has used passive devices since at least 1991, active devices since at least 1995. 92 See Carl Prine, FBI closely guards details of spy gear technology, Pittsburgh Tribune-Review, February 16, 2014, http://triblive.com/news/allegheny/5548583-74/fbi-technology-projects (“P bl c ec ds kept by t e fede l dep t ents eve led … Harris alone secured 68 FBI contracts worth at least $23.7 million. Purchases included Harris devices such as the StingRay, Amberjack, K ngf s nd G ss e t cke s, pl s sp e p ts nd cl ss nst ct n.”) See also Freedom of Information Act response from US Immigrations and Customs Enforcement to Christopher Soghoian, September 19, 2012, at page 13, available at https://www.documentcloud.org/documents/479397- st ng yf . t l#d c ent (“ICE s nvested $5,000,000.00 t w ds t e nvest ent f eq p ent nd t n ng n H s C p t n e v ces.”) See also Marisa Kendall and John Kelly, Cell tower dumps not used locally, The News-Press, December 8, 2013, available at http://www.news- press.com/article/20131208/CRIME/312080049/Cell-tower-dumps-not-used-l c lly (“[T e Fl d Department of Law Enforcement] has spent more than $3 million buying a fleet of Stingrays, records s w”). See also John Kelly, Cellphone data spying: It's not just the NSA, USA Today, December 8, 2013, available at http://www.usatoday.com/story/news/nation/2013/12/08/cellphone-data- spying-nsa-p l ce/3902809/ (“T e fede l g ve n ent f nds st f t e [ t ngR y] p c ses, v anti-te g nts.”) 93 For a discussion of the statutory authorities used by law enforcement to acquire cellular phone location data along with an analysis of multiple court opinions addressing law enforcement access to location data, see generally Stephanie K. Pell & Christopher Soghoian, Can You See Me Now?: Toward Reasonable Standards for Law Enforcement Access to Location Data That Congress Could Enact, 27 Berkeley Tech. L.J. 117 (2012). For information about the frequency or regularity with which federal, state and local law enforcement make requests for location data from carriers, see generally collections of files posted at http://www.markey.senate.gov/documents/2013-10- 03_ATT_re_Carrier.pdf and http://www.markey.senate.gov/documents/2013-12- 09_VZ_CarrierResponse.pdf (describing carrier disclosure of real-time and historical location data to law enforcement agencies).

19

Fourth Amendment constraints); (2) the frequency or regularity with which such technology is used by federal, state and local law enforcement; (3) the types of investigations or actual factual scenarios where law enforcement agencies have used the technology; and (4) any related prosecution-based and policy-driven considerations for the retention of data collected by an IMSI catcher. This Part will present and analyze the limited case law and publicly available DOJ guidance in an attempt to describe the policies and rules governing federal law enforcement genc es’ use of this technology. A. THE 1995 DIGITAL ANALYZER MAGISTRATE OPINION94 Despite their use since at least 1991,95 it was not until 1995 that a federal magistrate judge in California published the first decision analyzing a government application to use a digital analyzer.96 In this matter, the government wanted court authorization to use a passive surveillance device t “ n lyze s gn ls e tt ng f any cellular phone used by any one of five named subjects of a criminal nvest g t n.”97 The agents likely needed to use this technology because they did not know the particular phone numbers of the phones that the targets were using, and thus could not seek surveillance assistance from the t gets’ wireless carriers.98 It also appears that agents wanted to determine with whom the targets were communicating, information they could obtain in real-time by intercepting signals as calls took place.99 Following what was likely the DOJ policy at the time,100 the government sought a pen register order authorizing the surveillance. Magistrate Judge Edwards denied

94 Our analysis of this magistrate opinion draws from our previous article, Stephanie K. Pell & Christopher Soghoian, A Lot More Than A Pen Register, and Less than A Wiretap: What the StingRay Teaches Us About How Congress Should Approach the Reform of Law Enforcement Surveillance Authorities, 16 Yale J.L. & Tech 134, 157-160 (2013). 95 See Glen L. Roberts, Who's On The Line, supra **. 96 In the Matter of the Application of the United Sates of America for an Order Authorizing the Use of A cellular Telephone Digital Analyzer, 885 F.Supp. 197 (1995). The government submitted an ex parte application for an order permitting agents of the Orange County Regional Narcotics Suppression Program ("RNSP") to use a digital analyzer. Id. at 198-99. 97 Id. at 199. 98 The opinion notes that agents could not identify the particular cellular telephones they wished to n lyze. R t e , “ ppl c nt seeks t n lyze s gn ls e tt ng f ny cell l p ne sed by ny ne of five named subjects of a criminal investigation.” Id. 99 Id. Information about who targets are communicating with is often relevant to identifying the scope of the alleged criminal activity, to include the identity of additional criminal targets that may not be known to law enforcement. It would not, however, be necessary for the agents to continue to use a digital analyzer to determine the phone numbers the target phone was calling and was called by once the target phone was identified through its unique identifying number. Rather, agents could subpoena historical telephone toll records from the relevant cell phone provider(s) or obtain a Pen/T p de t c llect “ e l t e” ec ds f t e p v de (s) eflect ng t s nf t n. Indeed, once target phones are appropriately identified through their unique numbers, more traditional forms of carrier-assisted surveillance can proceed. 100 See discussion supra Part III B.

20

t e g ve n ent’s ppl c t n w t t p ej d ce, explaining that a Pen/Trap court de w s n t eq ed bec se t e Pen/T p st t te l ts ts ppl c t n “t dev ce ‘w c ec ds dec des elect n c t e p lses w c dentify the numbers dialed or otherwise transmitted on the telephone line to which such device is attached . . . .’”101 Judge Edwards noted that, because the digital analyzer was not intended to be nor could be physically attached to the cellular phone, the Pen/Trap statute was not applicable to its use.102 Judge Edwards also found, pursuant to the third party doctrine as articulated in Smith v. Maryland,103 t t t e g ve n ent’s se f d g t l n lyze sed n Fourth Amendment concerns.104 The Court noted that “[n] be s d led by telephone are not the subject of a reasonable expectation of privacy . . . [and] no l g c l d st nct n s seen between telep ne n be s c lled nd p ty’s wn telephone number (or [device serial] number), all of which are regularly voluntarily exp sed nd kn wn t t e s.”105 Although Judge Edwards ruled that the Pen/Trap statute did not regulate the passive surveillance technology the government sought to use—that is, it neither authorized nor prohibited its use—the judge expressed serious reservations about its use by law enforcement.106 Specifically, the judge expressed concern about both the privacy of innocent third parties in range of the device and a lack of adequate

101 See In the Matter of the Application of the United States of America for an Order Authorizing the Use of A cellular Telephone Digital Analyzer, 885 F.Supp. at 200. 102 Id. T e C t f t e expl ned ts e s n ng: “T e st t t y def n t n f ‘t p nd t ce dev ce’ does not include the limitation in the definition of a pen register described above, limiting the devices to those that are attached to a telephone line. See 18 U.S.C. § 3127(4). Nonetheless, it appears from the construction of related sections of the statutes governing trap and trace devices that they include only devices that are attached to a telephone line. Specifically, 18 U.S.C. § 3123(b) requires that an de f se f b t pen eg ste s nd t p nd t ce dev ces ncl de ‘t e n be nd, f kn wn, physical location of the telephone line to which the pen register or trap and trace device is to be tt c ed....’ T s limitation on the proscription against pen registers and trap and trace devices to p b t nly dev ces t t e ‘ tt c ed’ t telep ne l ne c nn t be ss ed t be n dve tent. In other statutes relating to interceptions of telephone communications, Congress encompassed, generally, any types of interceptions of wire, oral, or electronic communications—regardless of w et e t e nte cept ng dev ce w s ‘ tt c ed’ t telep ne l ne. ee, e.g., 18 U. .C. § 2511. T t Congress did not impose equally comprehensive restrictions on lesser interceptions that do not raise 4th Amendment issues, such as those made with pen registers and trap and trace devices, is neither s p s ng n nc ns stent.” In ny event, t st be e e be ed t t t e p b t n g nst the use of pen registers and trap and trace devices without court order is found in a criminal statute. See 18 U.S.C. § 3121(d). Under well-settled principles, the statute should be strictly construed, and any ambiguity in its scope must be construed na wly.” Id. 103 Smith v. Maryland, 442 U.S. 735 (1979). 104 In the Matter of the Application of the United States of America for an Order Authorizing the Use of A cellular Telephone Digital Analyzer, 885 F.Supp. at 199. 105 Id. 106 Id. at 201.

21

congressional oversight.107 If the court were to authorize the government’s use of a digital analyzer to identify the particular phones used by known targets, the judge acknowledged that such an order would essentially permit agents to intercept signals emitted from all phones in the t get’s area.108 Thus, in addition to the unique serial numbers identifying the targets’ phones, the digital analyzer would also identify the serial numbers of phones used by innocent third-parties.109 Judge Edw ds ec gn zed t t “depend ng p n t e effect ve nge f t e d g t l n lyze , telephone numbers and calls made by others than the subjects of the investigation c ld be n dve tently nte cepted.”110 The court also expressed concern that an order, if granted, would permit the government to collect data about large numbers of phones without any record keeping or reporting requirements, thus preventing effective congressional oversight of the surveillance tool. The c t c nt sted t s “l ck f ec d p d ct n” w t t e st t t y ep t ng eq e ents n t e Pen/T p st t te, such s “t e se f c t de s t t dent f ed p t c l telep nes nd t e nvest g t ve gency” nd “pe d c ep ts t C ng ess st t ng t e n be s f s c de s.”111 Noting these differences and others,112 the court found that the g ve n ent’s ppl c t n “w ld n t ns e s ff c ent cc nt b l ty.”113 Although clearly troubled by the surveillance capabilities of this technology, the court could not restrain its use by law enforcement.114 M e ve , t e c t’s determination that neither the Fourth Amendment nor the Pen/Trap statute authorized, restricted or otherwise regulated law enforcement use of the technology l kely e nf ced DOJ’s v ew that it did not need court authorization for use of a

107 Id. 108 Id. 109 Id. 110 Id. The court also noted that although the agents were not seeking to intercept communications content, the digital analyzer they used could be programmed for that purpose. Id. at 199. See also DOJ Electronic Surveillance Bulletin, September 1997 at 14 (“Alt g [ d g t l n lyze ] dev ce s also capable of intercepting both the numbers dialed from the cellular phones and the voice (wire) communications to and from cellular telephones, the digital analyzer is programmed so it will not intercept cellular conversations or dialed numbers when it is used for the limited purpose of seizing E Ns nd/ t e cell l telep ne’s n be .”). See also Electronic Surveillance Unit, Electronic Surveillance Manual: Procedures and Case Law Forms, U. . Dep’t f J st ce 40 (2005) at 40, http://www.justice.gov/criminal/foia/docs/elec-sur-manual.pdf. ( e e fte “2005 Elect n c ve ll nce M n l)(“D g t l n lyze s/cell s te s l t s/t gge f s nd s l dev ces y be capable of intercepting the contents of communications and, therefore, such devices must be configured to disable the interception function, unless interceptions have been authorized by a Title III de .”). 111 Id. at 201-02 citing 18 U.S.C. §§ 3123(b), 3126. 112 See In the Matter of the Application of the United States of America for an Order Authorizing the Use of A cellular Telephone Digital Analyzer, 885 F.Supp. at 201-202. 113 Id. at 201. 114 T e c t den ed t e g ve n ent’s ppl c t n bec se t f nd t t t e Pen/T p st t te w s n t applicable to a digital analyzer. The court noted that the government was seeking the application nly “ n n b nd nce f c t n.” Id. at 200.

22

digital analyzer, even if it advised prosecutors to seek court authorization in an abundance of caution or as a matter of policy.115 This position was later articulated in an internal DOJ document in 1997. B. THE 1997 DOJ GUIDANCE A document published by DOJ in 1997, initially distributed nationally to prosecutors116 nd l te p bl s ed n DOJ’s webs te, is the earliest publically available DOJ document that describes the capabilities of passive and active wireless phone surveillance technology.117 The document ( e e fte “1997 DOJ Guidance”) also discusses, again for the first time, the legal policies governing t e tec n l gy’s use by federal law enforcement agents.118 In this document, DOJ took the position that, as long as (1) law enforcement agents were not intercepting communications content and (2) the acquisition of the non- c ntent d t d d n t nv lve t e ss st nce f c e s, “ t d es n t ppe t t t e e are constitutional or statutory constraints on the warrantless use of [an active or p ss ve s ve ll nce] dev ce.”119 In other words, DOJ appears to have recognized no 115 T e C t’s e s n ng ppe s t ll st te ts c nce n t t f t g nted s c n de —even “ n n b nd nce f c t n” —pursuant to a statute whose definitional elements did not conform to the surveillance technique at issue, it risked giving: (1) a potentially incorrect interpretation of a statute; or worse (2) judicial approval of a surveillance technique that Congress appeared neither explicitly t t ze n p b t nde t e st t t y t ty p esented n t e g ve n ent’s ppl c t n without the corresponding accountability mechanisms that Congress mandated in the statute cited in t e g ve n ent’s ppl c t n. 116 See Executive Office for United States Attorneys, Electronic Investigative Techniques, USA BULLETIN, Sept. 1997, http://www.justice.gov/usao/eousa/foia_reading_room/usab4505.pdf [hereinafter 1997 DOJ Guidance] (USA Bulletins are published by the Executive Office of United States Attorneys (EOUSA) nd d st b ted t Un ted t tes Att ney’s Off ces c ss t e c nt y. T ey c ve nge f t p cs and issues (like law enforcement surveillance methods) of interest to federal prosecutors, to include new case law, law enforcement tools and practices, statutory authorities and internal DOJ guidance.). 117 Id. at 13-14 (describing the types of information that digital analyzers and cell site simulators acquire). 118 Id. at 13-15. 119 pec f c lly, DOJ e s ned t t “T tle III’s p v s ns (18 U. .C. §§ 2510-2522) would not apply to the use of a digital analyzer or a CSS when they are used to capture call processing information (MIN, ESN, cell site location, status of call, etc.) because they do not intercept the contents of any wire, oral, or electronic communication as the term ‘contents’ is defined by Title III. Currently, Section 2510(8) st tes, ‘c ntents, w en sed w t espect t ny w e, l, elect n c c n c t n, ncl des ny information concerning the substance, purport, or meaning of that information.’ ESNs/MINs and other automatic call processing information that are technologically necessary for the service provider to process cellular calls are not the types of transmissions Congress included within Section 2510(8)’s def n t n f ‘contents’ when it was amended in 1986. [See S. Rep.No. 541, 99th Cong., 2d Sess. 13 (1986)].” M e ve , DOJ sse ts “t e e s n ‘electronic communication’ [as defined by 18 U.S.C. § 2510(12)] nless t e MIN E N s “t nsmitted in whole or in part by a wire, radio, electromagnetic, photo elect n c, p t pt c l syste t t ffects nte st te f e gn c e ce.” A t ns ss n normally contemplates a sender and a receiver. The ECPA legislative history regarding the definition

23

need for a warrant or other judicial process requirement for law enforcement use of digital analyzers and cell cite simulators when they are only employed to intercept non-content data (including location data and real time numbers, called and received) without the assistance of carriers, whether in relation to specific targets or innocent third-parties. Although concluding that law enforcement use of these direct, unmediated interception devices did not require any legal process, the 1997 DOJ Guidance, as a matter of policy, advises that “t t e extent [cell s te s l t s] nd d g t l analyzers are used as pen registers or trap and trace devices, they should only be sed p s nt t c t de ss ed p s nt t t ese st t tes.”120 When law enforcement wants to determine in real time the calls made and received by a particular phone, the government can obtain a court order compelling a service provider to install a pen register or trap and trace device.121 This disclosure of information involving carrier assistance is regulated by statute, whereas the digital analyzer and cell site simulator technology enables government agents to obtain the same information directly from cell phones without any statutory process requirement. Perhaps in an effort to reconcile this disparity in regulation, arguably as early as 1995122 but certainly by 1997, DOJ advised prosecutors and agents to

f w e c n c t n w ns g nst n p pe ec n c l e d ng f t e p se “ n w le n p t. . . by t e d f w e. . .” nd st tes t t t e p se “ s ntended t efe t w e t t c es t e communication to a significant extent from the point of origin to the point of reception, even in the same building. It does not refer to wire that is found inside the terminal equipment at either end of t e c n c t n.” [ . Rep. 99-541, 12.] Thus, it does not appear that MINs and ESNs ‘forced’ from the cellular telephone by the CSS or obtained by a digital analyzer are ‘electronic communications’ w t n t e c nte pl t n f 18 U. .C. § 2510(12).” DOJ further excludes collection of cell cite information from with a digital analyzer or cell site s l t f t ed C n c t ns Act ( CA) st t t y eq e ents: “If cell s te nf t n s treated as a subscriber record or other information rather than a contemporaneous electronic communication covered by Title III, then 18 U.S.C. § 2703 (regarding stored electronic communications) might apply. It should be noted, however, that Section 2703 controls disclosures by service providers to Government entities and does not prohibit the Government from obtaining such information on its own without involving the service provider. Additionally, because CSSs and digital analyzers do not access communications in electronic storage in a facility with electronic c n c t n se v ce, ect n 2703 d es n t pply.” Id. at 14. 120 Id. at 14 (noting that the g d nce t seek Pen/T p de s “Dep t ent p l cy.”) Id. 121 See 18 U.S.C. §§ 3121–3127 (2012) (authorizing law enforcement to install and use a pen register dev ce t “ ec [d] dec d[e] . . . [n n-content] dialing, routing, addressing, or signaling information . . . transmitted by an instrument or facility for which a wire or electronic communication is t ns tted [ ] p v ded ” nd t nst ll nd se t p nd t ce dev ce t “c pt [e] t e nc ng electronic or other impulses which identify the originating number or other dialing, routing, addressing, and signaling information reasonably likely to identify the source of a wire or electronic communication, provided, however, that such information shall not include the contents of any communicati n”). 122 DOJ s g t Pen/T p de f J dge Edw ds “ n n b nd nce f c t n.” See supra note **.

24

seek Pen/Trap court process when using a digital analyzer/cell cite simulator as a Pen/Trap device.123 The 1997 DOJ Guidance also recognized that digital analyzers and similar technologies could capture cell site location data (to include cell cite data for target phones as well as innocent third party phones).124 While the capability to acquire location data directly may not have raised significant Constitutional or policy- el ted “ ed fl gs” t DOJ n 1994125 or 1997, determining and fixing the proper legal standard(s) for authorizing law enforcement access to location data has become the subject of considerable debate in both the courts and Congress.126 C. 2001 USA PATRIOT ACT AMENDMENTS TO PEN/TRAP STATUTE AND GUIDANCE IN THE 2005 ELECTRONIC SURVEILLANCE MANUAL While the PATRIOT Act is generally not thought of as privacy-enhancing legislation, it did bring law enforcement use of passive and active cellular surveillance technology under some limited degree of judicial supervision and congressional oversight through specific definitional changes to the Pen/Trap statute. Whereas the pre-2001 pen eg ste def n t n nly ppl ed t “n mbers dialed or t e w se t ns tted,” t e PATRIOT Act dded t e te “s gn l ng nf t n.”127 T e 2005 ed t n f DOJ’s Elect n c ve ll nce M n l expl ns t t “‘[s] gn l ng nf t n’ s b de te t t enc p sses t e k nds f n n-content

123 The 1997 DOJ Guidance does not, however, give any similar guidance with respect to direct (non- carrier assisted) collection of cell phone location data. In other words it does not advise agents and prosecutors to obtain the same legal process used to compel location data from carriers. 124 1997 DOJ Guidance, supra note ** t 14. (D g t l n lyze s nd cell s te s l t s “c n c pt e t e cell site codes identifying the cell location and geographical sub-sector from which the cellular telep ne s t ns tt ng; t e c ll’s nc ng tg ng st t s; t e cell l telep ne s t ns tt ng; t e c ll’s nc ng tg ng st t s; t e telep ne n be s d led (pen register order required); and the date, time, and duration of the call. This cell site data is transmitted continuously from a cellular telephone (not by the user) as a necessary part of call direction and p cess ng.”). Id. 125 In 1994, the Office of Enf ce ent Ope t ns (OEO) p ned t t “ nvest g t s d d n t need t obtain any legal process in order to use cell phone tracking devices so long as they did not capture the numbers dialed or other information "traditionally" collected using a pen/trap dev ce.” 2005 Electronic Surveillance Manual, supra n te ** t 45. B ck n 1994, OEO c ncl ded t t t e “’s gn l ng nf t n’ t t c lly t ns tted between cell p ne nd t e p v de 's t we d es n t implicate either the Fourth Amendment or the wiretap statute because it does not constitute the ‘c ntents’ f c n c t n.” Id. M e ve , t e 1994 n lys s e s ned “t t t e pen/t p st t te d d n t pply t t e c llect n f s c nf t n bec se f t e n w def n t ns f ‘pen eg ste ’ nd ‘t p nd t ce dev ce.’” Id. T e ef e, “’s nce ne t e t e c nst t t n n ny st t te eg l ted t e se, s c dev ces d d n t eq e ny leg l t z t n t pe te.’” Id. 126 See generally Pell & Soghoian, supra note 94(Describing the current congressional debates over proper legal standard(s) and analyzing various magistrate opinions requiring different legal standards for law enforcement access to location data.). 127 See 18 U. .C. § 3127(3) def n ng pen eg ste s “ dev ce p cess w c ecords or decodes dialing, routing, addressing, and signaling information transmitted by an instrument or facility from w c w e elect n c c n c t n s t ns tted.”

25

nf t n sed by c n c t n syste t p cess c n c t ns.” Indeed, DOJ nst cted p sec t s t t t e new pen eg ste def n t n “ ppe s t encompass all of the non-c ntent between cell p ne nd p v de ’s t we .”128

128 l ly, t e def n t n f “t p nd t ce” dev ce, w c g n lly ncl ded nly “t e g n t ng n be f n nst ent dev ce” exp nded t ncl de “t e g n t ng n be t e d l ng, routing addressing, and signaling information reasonably likely to identify the source of a wire or elect n c c n c t ns.” See 18 U.S.C. § 3127(4). Like the expanded definition of pen register, DOJ nst cts t t t e new t p nd t ce def n t n n w “ ppe s t ncl de s c nf t n s t e transmission of a MIN [or other type of unique identifying number], which identifies the source of a c n c t ns.” 2005 Elect n c ve ll nce M n l, supra note ** at 46. DOJ’s c ncl s n t t Pen/T p n w enc p sses ll n n-content data between a cell phone and a cell t we w s b sed, n p t, n ts n lys s f t e elev nt b t “sc nt” leg sl t ve st y w c s ggested t t t e new def n t ns we e ntended t pply t “ ll c n c t ns ed , nste d f f c s ng n t d t n l telep ne c lls.” Id. Ex n ng, f ex ple, H se l ng ge efe enc ng “ packet requesting a telnet session—a piece of information passing between machines in order to est bl s c n c t n sess n f t e n se ,” DOJ s ggests t t t e te “p v des cl se analogy to the information passing between a cell phone and a tower in the initial stages of a cell p ne c ll.” Id. at 47. Moreover, in contrast to earlier Pen/Trap definitions that referenced the attachment of a Pen/Trap device to a phone line, the House Report recognized that Pen/Trap devices “c ld c llect nf t n e tely.” Id. at 46. It s ld be n ted, weve , t t DOJ d ew d st nct n between st nd ds t z ng “ ff ” collection of cell phone location data via digital analyzers and IMSI catchers and the collection of these data through compelled disclosures from carriers. Indeed, in 1994, the Communications Ass st nce f L w Enf ce ent Act (CALEA) nst cted t t “ ny nf t n t t y d scl se t e p ys c l l c t n f [ telep ne se v ce] s bsc be ” y not be cq ed “s lely p s nt t t e authority for pen registe s nd t p nd t ce dev ces.”( ee 47 U. .C. § 1002( )(2) (2010)). DOJ p ned t t, “[b]y ts ve y te s, t s p b t n ppl es nly t nf t n c llected by p v de and not to information collected directly by law enforcement authorities. Thus, CALEA does not bar the use of pen/trap orders to authorize the use of cell phone tracking devices used to locate targeted cell p nes.” 2005 Elect n c ve ll nce M n l, supra note ** at 47. As applied to compelled disclosures of prospective location information from carriers, the CALEA dictate meant that DOJ had to find another authority to pair with or replace Pen/Trap authority.128 Since at least 2005, DOJ has been advising prosecutors to obtain both a Pen/Trap order and an 18 U.S.C. § 2703 (d) order (D Order). (See Pell & Soghoian, supra note 94 at 135-37). Moreover, some g st te j dges ve eq ed “p b ble c se” se c w nts bef e ss es de s t z ng law enforcement to compel a provider to track a cell phone in real time. Id. at 137-39. As referenced earlier, the appropriate standard(s) for law enforcement compelled disclosures of historical and prospective location data remains an unresolved issue for the courts and Congress. See supra **. For purposes of this discussion, however, t s s ff c ent t n te t t b t D O de nd “p b ble c se” w nt st nd d s e st ngent t an Pen/Trap. To obtain a Pen/Trap order, the g ve n ent need e ely “ce t fy” t t t e nf t n s g t “ s elev nt nd te l t n ng ng cri n l nvest g t n.” See 18 U. .C. § 3122(b)(2) (2012). c “ce t f c t n” d es n t eq e ny fact finding by a magistrate judge. See Pell & Soghoian, supra note 95 at 155-56. In contrast, to obtain a D Order, the government must assert and a judge m st f nd “spec f c nd t c l ble f cts” t t t e l c t n nf t n s g t “ s elev nt nd te l t n ng ng nvest g t n.” See 18 U.S.C. § 2703(d). The requirement for a search warrant is even more stringent, as the government must show and a magistrate must find that there is probable cause to believe that the location information w ld be “ev dence f c e.” See Fed. R. Crim. P 41(c)(1). Notwithstanding that compelling location data from a carrier would require a more stringent standard than that found in the Pen/Trap st t te, DOJ’s 2005 G d nce t k b t t e leg l nd p l cy p s t n t t Pen/T p de w s

26

These expanded Pen/Trap definitions had implications for law enforcement direct collection of mobile device serial numbers, the real-time monitoring of numbers called and received, as well as acquiring location information. Specifically, post- PATRIOT Act, DOJ took the position that all forms of non-content data collected directly required prosecutors to obtain a Pen/Trap court order.129 D. 2012 CELL SITE SIMULATOR (“STINGRAY”) MAGISTRATE OPINION130 With the passage of the PATRIOT Act in 2001, DOJ took the position that a Pen/Trap order was necessary to authorize law enforcement use of direct surveillance technology, like a StingRay, to intercept non-content data. It would take more than a decade, however, for a federal magistrate judge to publish an opinion evaluating an application for law enforcement use of a direct, active interception device.131 In 2012, a federal magistrate judge from Texas issued an order denying an application submitted by agents from the Drug Enforcement Agency for the use of a StingRay.132 The government s g t Pen/T p de “t detect d s gn ls emitted from wireless cellular telephones in the vicinity of the [Subject] that identify t e telep nes.”133 Agents submitted their application pursuant to 18 U.S.C. §§ 3122 (a)(1), 3127(5) (the Pen/Trap statute) and 2703(c)(1) (a provision of the Stored Communications Act)134 and the government informed Magistrate Judge Owsley

sufficient for direct collection of cell phone location data by law enforcement. 2005 Electronic Surveillance Manual, supra note ** t 47. (“CALEA [t e C n c t ns Ass st nce f L w Enforcement Act] does not bar the use of pen/trap orders to authorize the use of cell phone tracking dev ces sed t l c te t geted cell p nes.”). Id. 129 2005 Electronic Surveillance Manual, supra note ** at 45-47. 130 Our analysis of this magistrate opinion draws from our previous article, Stephanie K. Pell & Christopher Soghoian, A Lot More Than A Pen Register, and Less than A Wiretap: What the StingRay Teaches Us About How Congress Should Approach the Reform of Law Enforcement Surveillance Authorities, 16 Yale J.L. & Tech 134, 160-163 (2013). 131 One likely reason for this time gap is the default sealing of all pen register applications and orders with no corresponding requirement that they be unsealed o ts de f t e p sec t n’s d sc ve y obligations to indicted criminal defendants as part of the criminal discovery process. See generally, Stephen Wm. Smith, Gagged, Sealed and Delivered: Reforming ECPA’s Secret Docket, 6 H v. L. & P l’y Rev. 313 (2012). (“T g p tent x f ndef n te se l ng, n nd scl s e ( .e. g gg ng), nd delayed-notice provisions, ECPA [Electronic Surveillance Privacy Act] surveillance orders all but v n s nt leg l v d.” Id. at 314. The Pen/Tap statute is Title III of ECPA. See Pub. L. No. 99- 508, tit. III, 100 Stat. 1848, 1868–1873 (codified as amended at 18 U.S.C. §§ 3121–3127 (2010)). 132 In the Matter of The Application of the United States of America for An Order Authorizing the Installation and Use of a Pen Register and Trap and Trace Device, 890 F. Supp. 2d 747, 748 (S.D. Tex. 2012). A target had switched from using a phone known to agents to an unknown phone. Id. The gent le d ng t e nvest g t n nd c ted t t t e “eq p ent des gned t c pt e t e cell p ne numbe s w s kn wn s ‘[ ]t ng[R] y.’” Id. 133 Id. 134 It s n t cle f t e 2012 g st te p n n w t p p se t s c t t n t ECPA’s t ed Communications Act served in terms of providing additional authority of unmediated, direct collection of non-content data in this investigation. The 2005 Guidance indicated that only a

27

t t t w s “b sed n st nd d ppl c t n del nd p p sed de pp ved by [DOJ].”135 Since the subject was known to law enforcement (whereas his phone was unknown), agents planned to identify the phone by capturing device identification d t “ t v s l c t ns n w c t e [ bject’s] telep ne [w ld] e s n bly [be] bel eved t be pe t ng.”136 After reviewing the application, Judge Owsley conducted an ex parte hearing nd lt tely den ed t e g ve n ent’s application.137 Judge Owsley expressed concern that the application did not explain adequately either the technology itself “ w ny s ve ll nce s tes t ey intend[ed] to use, or how long they intend[ed] to operate the [S]ting[R]ay eq p ent t g t e ll telep ne n be s n t e ed te e .”138 Moreover, the Court noted that no explanation was given, either in writing or verbally, as to what w ld be d ne w t t e “ nn cent nf t n” c llected f t e p nes f uninvolved individuals who just happened to be in the area under surveillance.139 Finally, the court expressed concern that neither the prosecutor nor the DEA agent appeared to understand the technology at issue nd “see ed t ve s e d sc f t n t y ng t expl n t.”140 N tw t st nd ng t ese c nce ns, t e C t’s dec s n t deny t e ppl c t n appears to stem from a definitional problem it identified in the Pen/Trap statute that the government did not adequately address during the application or ex parte hearing process. While recognizing that the PATRIOT Act broadened the Pen/Trap def n t ns, “ pl fy[ ng] t e v s types f nf t n t t e v l ble s c s t ng nd s gn l ng nf t n,”141 Judge Owsley interpreted § 3123(b)(1) of the pen eg ste st t te s “st g tf w d n t t telep ne n be s l identifier is necessary f pen eg ste .”142Accordingly, the judge found that the l ng ge n t e st t te “ ndate[s] that this Court have a telephone number or s e s l dent f e bef e ss ng n de t z ng pen eg ste .”143 Because the government did not provide any support to the contrary in case law or

Pen/Trap order was required for use of devices to collect non-content data directly. See 2005 Electronic Surveillance Manual, supra note ** at 47-48. DOJ may, however, have provided updated guidance reflecting a different or more nuanced legal position. As of the writing of this Article, this new guidance, if it exists, is not publically available. 135 In the Matter of The Application of the United States of America for An Order Authorizing the Installation and Use of a Pen Register and Trap and Trace Device, 890 F. Supp. 2d 747, 749 (S.D. Tex. 2012). 136 Id. at 748. 137 Id. at 748, 752. 138 Id. at 749. 139 Id. 140 Id. 141 Id. at 751. 142 Id. 143 Id.

28

any other authority suggesting that the statute authorized collection of non-content data from unidentified devices, the judge denied application without prejudice.144 D. THE RIGMAIDEN FEDERAL PROSECUTION In 2011, a decade after the Harris Corporation introduced the StingRay,145 t e FBI’s use of the device finally surfaced during the pre-trial stages of a criminal case.146 The government prosecuted Daniel David Rigmaiden (“R g den”) for his role in a scheme in which he allegedly obtained fraudulent tax refunds for hundreds of deceased persons and other third parties.147 After a lengthy investigation, federal gents l c ted R g den, n p t by t ck ng t e l c t n f “[ wireless data-card] c nnected t l pt p c p te ” n s p t ent.148 The government did not know R g den’s ct l dent ty nt l gents ested .149 Indeed, t e g ve n ent’s only solid lead was an IP address associated with the prepaid Verizon data-card that Rigmaiden used to transmit fraudulent tax returns to the IRS.150 To narrow down the location of the data-card, the government obtained historical cell-site records from Verizon. Those records determined t e d t c d’s location to be within an approximately one-quarter square mile area. As Verizon did not have the technical capability to provide higher-accuracy location information,151 the government used a StingRay to locate the data-card, le d ng t e gents t R g den’s p t ent.152

144 Id. at 751-52. 145 See discussion supra Part **. 146 United States v. Rigmaiden, Case 2:08-cr-00814-DGC. See also Jennifer Valentino-Devries, 'Stingray' Phone Tracker Fuels Constitutional Clash, Wall St. J., Sept. 22, 2011, ttp:// nl ne.wsj.c / t cle/ B10001424053111904194604576583112723197574. t l (“A stingray's role in nabbing the alleged "Hacker"— Daniel David Rigmaiden —is shaping up as a p ss ble test f t e leg l st nd ds f s ng t ese dev ces n nvest g t ns.”). 147 The government indicted Daniel David Rigmaiden (Rigmaiden) in a superseding indictment on 74 counts of wire fraud, aggravated identify theft, mail fraud and a conspiracy to commit these offenses. United States v. Rigmaiden, Case 2:08-cr-00814-DGC; DE 200. In April 2014, Rigmaiden plead guilty to four felony counts of mail fraud, wire fraud and conspiracy to commit these offenses. He was sentenced to time served which amounted to the 63 months he spent in prison awaiting trial. See Dennis Wagner, Tax Scammer Rigmaiden Pleads Guilty, Gets Time Served, AZCentral, April 8, 2014; http://www.azcentral.com/story/news/politics/2014/04/07/rigmaiden-tax-scammer-pleads- guilty/7448151/ 148 Id. Court Order DE 1009 at 1. 149 Id. Court Order DE 1009 at 1-6. 150 Id. Court Order DE 1009 at 1-4. 151 See supra, Part II.B(2) and n.79 (explaining how E-911 regulations to do not require carriers to be able to locate data-only devices in real-time.). 152 United States v. Rigmaiden, Case 2:08-cr-00814-DGC; See DE 484-6 at 61(USPIS Inspector James L. W ls n st tes n n Invest g t n Det ls ep t t t “On 7/16/08, we were informed that they were ble t t ck s gn l nd we e s ng ‘ t ngR y’ t p np nt t e l c t n f t e c d.”) https://ia600707.us.archive.org/33/items/gov.uscourts.azd.396130/gov.uscourts.azd.396130.484.6 .pdf

29

Prior to locating the data-card, the government obtained a search warrant pursuant to Rule Fed. R. Crim. P 41(b) authorizing the use of a cell site simulator.153 After his arrest, Rigmaiden filed a motion to suppress, arguing that the government had repeatedly violated the Fourth Amendment in its efforts to locate him.154 Ultimately, the government conceded arguendo t t ts eff ts t l c te R g den’s d t -card constituted a Fourth Amendment search and seizure.155 A key question to consider is why the government chose to make this concession when t e DOJ’s 2005 Guidance did not advise that digital analyzers and cell site simulators raised any Fourth Amendment issues that would necessitate securing a warrant. Is there a more nuanced DOJ position directing or advising prosecutors to obtain a warrant when the use of a cell site simulator may reveal the location of a device to be inside a home or other protected space?156

153 Id. Court Order DE 1009 at 21 (“[T] e g ve n ent bt ned de CR-08-90330 (t e ‘T ck ng W nt’) f Un ted t tes M g st te J dge R c d eeb g f t e N t e n D st ct f C l f n . Doc. 470-1 at 28. The Tracking Warrant was issued under Rule 41(b) of the Federal Rules of Criminal Procedure and other statutes. Id. Judge Seeborg found that the application for the warrant est bl s ed ‘p b ble c se t bel eve t t t e se nd n t ng f b le t ck ng dev ce’ w ld ‘le d t ev dence f’ seve l spec f c c es, ncl d ng conspiracy to defraud the government, fraud el t ng t dent ty nf t n, gg v ted dent ty t eft, nd w e f d, ‘ s well s t t e dent f c t n f nd v d ls w e eng ged n t e c ss n f t ese ffenses.’”). 154 R g den’s t n t s pp ess d v des t e g ve n ent’s nvest g t ve ct ns nt twenty-one d ffe ent se c es. In ts O de dd ess ng R g den’s M t n t pp ess, t e D st ct C t g ped t e lleged se c es, t e defend nt’s c llenges nd t e g ve n ent’s esp nses nto the f ll w ng c teg es: “w et e Defend nt d leg t te expect t n f p v cy n t e l c t n f t e c d; t e g ve n ent’s c llect n f st c l cell-site information, destination IP addresses, nd d t f t e D c l p t ent’s l company; the search for the aircard using the mobile t ck ng dev ce; t e se c es f Defend nt’s p t ent nd c p te ; nd w et e t e F t A end ent’s g d f t except n ppl es.” Id.; Court Order DE 1009 at 6-7. 155 Id. G ve n ent’s Me nd Re M t n f D sc ve y, DE 674 t 1 (“[T] e Un ted t tes p p ses t t t e C t ss e, g end , f Defend nt’s M t n f D sc ve y nd ny forthcoming motion to suppress, that the aircard tracking operation was a Fourth Amendment se c nd se z e.”). See also Discovery Order, DE 723 at 14-15. In an order addressing the defend nt’s t n t s pp ess, t e d st ct c t s l ted ce t n f cts el ted t t e se f t e cell site simulator, some of which were stipulated to by the government, including: • ignals sent by the mobile tracking device to the aircard are signals that would not have been sent t t e c d n t e n l c se f Ve z n’s pe t n f ts cell t we s. • T e t ck ng pe t n w s F t A end ent se c nd se z e. • [T] e b le t ck ng dev ce [] l c ted t e c d p ec sely w t n Defend nt’s p t ent. 156 See United States v. Rigmaiden, Case 2:08-cr-00814-DGC; DE 1004 Transcript of Defendant R g den’s pp ess n He ng t 61. (D ng q est n ng by t e j dge, p sec tors explained, “We gene lly ec end [t e] se of a search warrant at a point where we think that we're going to reasonably be interrogating a device within an area where there's a reasonable expectation of

privacy, because we're—in going into that area where there's a reasonable expectation of privacy, we want to ensure a neutral and detached magistrate has made a finding of probable cause at that point. However, it's the same type of data that we're getting in both missions, because based upon the transmissions back and forth to the cell tower is what we would use to direction-find the cellular

device. With a pen register order, we—because the pen register order doesn't include a finding of probable cause by a magistrate, we will generally restrict our use there to where we're not knowingly going into an area where there's a reasonable expectation of privacy. . . . It's not the nature

30

If DOJ anticipated actual Fourth Amendment issues with its use of a cell site simulator to locate Rigmaiden, obtaining a warrant was a reasonable, prudent p ec t n. T e g ve n ent’s g end c ncess n, weve , s l ted to the defend nt’s t n t s pp ess n t e nst nt c se. In other words, DOJ did not take the position, arguendo or otherwise, that law enforcement use of a StingRay in every other, or even a single criminal investigation would constitute a Fourth Amendment search. Moreover, the government seems to shift positions on whether it believes the Fourth Amendment was implicated during some part of the tracking operation to locate Rigmaiden: At first, it suggests that (notwithstanding the arguendo c ncess n), t e t ck ng pe t n, “ s f ct l tte . . . d d n t nv lve se c se z e nde t e F t A end ent.”157 Later during direct questioning from the court, however, the government explained that it seeks a warrant when a cell site simulator would locate an individual in a protected space.158 At the end of the d y, t e 2011 R g den p sec t n p v des n cl ty b t t e g ve n ent’s view on when or if the use of a StingRay requires an agent to obtain a warrant. While it is impossible to discern all elements behind DOJ’s concession in this particular case, one aspect of the rationale emerges in the discovery, pre-trial motion practice and related hearings: the government considers cell site simulator tec n l gy t be sens t ve “s ce nd et d” t t it believes will be rendered less effective if its capabilities were revealed publicly, as future targets of surveillance would learn how to thwart the surveillance method. Accordingly, p sec t s ppe t ve de st teg c c ces t l t t e t ngR y’s exp s e n t e c se, ncl d ng n eff t t p tect t e dev ce’s n e.159 In response to certain Rigmaiden discovery requests, for example, the government argued that the tec n l gy sed t l c te t e Defend nt’s data-card and the manner in which the tec n l gy w s e pl yed w s “l w enf ce ent sens t ve” nf t n160 subject to

of the data; it's the nature of the interest. And the—the nature of the—the legal interests, the Fourth Amendment—you know, where you have an expectation of privacy is where we would recommend s ng t e se c w nt s pp sed t j st pen eg ste de .”). Indeed, t e p sec t s recognized that United States v. Kyllo, 53 US 27, 40 (2001), where the Court held that the “g ve n ent’s se f t e l g ng dev ce n t n gene l p bl c se, t expl e det ls f t e e t t w ld p ev sly ve been nkn w ble w t t p ys c l nt s n, . . . w s ‘se c ’ [ nd t s] p es pt vely n e s n ble w t t w nt,” w ld l kely pply t t e g ve n ent’s se f t ngR y t send s gn l t g w lls f n p t ent c plex t l c te R g den’s d t - card. See United States v. Rigmaiden, Case 2:08-cr-00814-DGC; T nsc pt f Defend nt R g den’s Suppression Hearing, DE 1004 at 63. 157 See United States v. Rigmaiden, Case 2:08-cr-00814-DGC; G ve n ent’s Me nd Re M t n For Discovery, DE 674 at n.1. 158 See supra note [currently 64]. 159 See United States v. Rigmaiden, Case 2:08-cr-00814-DGC; Affidavit of Supervisory Agent Bradley S. Morrison, the Unit Chief of the Tracking Technology Unit, Traditional Technology Section, Operational Technology Division, DE 674-1 t 1 (“T e ct l ke nd del f t e eq p ent sed in any particular operation by the FBI is law enforcement sensitive and pursuant to FBI policy, c nn t be ele sed t t e gene l p bl c.”). 160 United States v. Rigmaiden, Case 2:08-cr-00814-DGC; Court Order, DE 723 at 4-5.

31

qualified privilege recognized in Roviaro and Van Horn.”161 These cases essentially hold that the government can shield information about sensitive investigative techniques when a court determines that such disclosure would not be relevant or elpf l t t e defense t e w se “essent l t f dete n t n f c se.”162 So while Rigmaiden filed discovery motions to compel the government to disclose more information about the cell site simulator,163 t e g ve n ent’s c ncess n that the tracking operation was a Fourth Amendment Search presumably foreclosed the relevance of at least some details b t t e t ngR y nd l w enf ce ent’s se f the device (thereby preventing their public disclosure).164 That the government seeks to protect its use of cell site simulators as a sensitive source and method—to the extent that it will not even acknowledge the name of the specific equipment it uses165—is, however, consistent with a larger effort to prevent public disclosure of the technology and its capabilities. We address that effort next. IV. THE GOVERNMENT’S SECRET STINGRAY

161 Id. Citing Rovairo v. United States, 353 U.S. 53, 60-61(1957); US v. Van Horn, 798 F.2d 1492(11th Cir. 1986). 162 Rovairo v. United States, 353 U.S. 53, 60-61(1957). With respect to government surveillance equipment, the defendant-target of electronic surveillance is not entitled to learn the location and type of equipment used by the government unless he can show sufficient need for such information. U.S. v. Van Horn, 789 F2d 1492 (11th Cir. 1986). 163 See United States v. Rigmaiden, Case 2:08-cr-00814-DGC; Defend nt’s M t n f Add t n l D sc ve y D e t G ve n ent Ign ng Defend nt’s Recent Discovery Requests, DE 697. 164 See United States v. Rigmaiden, Case 2:08-cr-00814-DGC; G ve n ent’s Me nd Re M t n F D sc ve y, DE 674 t n. 3 (“[T] v d d scl s e f p v leged nf t n nd s pl fy t e Fourth Amendment analysis, the United States will concede, for purposes of any forthcoming motion t s pp ess, t t t e FBI l c ted t e c d w t n Un t 1122 f t e D c l Ap t ents.”). W t the “se c ” concession, the defendant is not harmed by any lack of disclosure—Rigmaiden gets to st t f t e p s t n t t t e g ve n ent’s ct ns c nst t ted F t A end ent se c nd seizure and can then make all arguments that flow from that position, while the government can protect details that it believes could assist potential targets in evading detection by the technology in the future. See DE 1009 t 6 (“T e C t [ s] c ncl ded . . . t t Defend nt w s f lly ble t ke s Fourth Amendment arguments in light of the extensive disclosures provided by the government, detailed stipulations of fact agreed to by the government, and information Defendant was able to obtain through his own investigations with the aid of investigators, legal assistants, and a laptop computer provided by the Court. . . Defendant has been placed at no disadvantage by the g ve n ent’s w t ld ng f sens t ve l w enf ce ent nf t n.”). Moreover, because law enforcement can generally switch to carrier-assisted surveillance once a cell site simulator is used to identify a target, it is feasible to exclude the use of IMSI catcher technology f t e g ve n ent’s c se-in-chief trial evidence. In other words, because an IMSI catcher may only be initially necessary to identify or locate a target (which may not be relevant proof of the charges at trial), additional tracking of a target, when needed, can be performed with carrier-assisted surveillance, which can be used as evidence at trial without fear of exposing a sensitive source or et d. Indeed, n t e R g den p sec t n, t e c t n tes t t “t e g vernment has never suggested that it intended to present evidence about its location of the aircard [i.e. data-card] at t l.” Id. Court Order, DE 723 at 5. 165 See supra note ** [FN containing Morrison Affadavit].

32

Based on the recent public disclosure of an affidavit by Agent Bradley S. Morrison,166 t e e d f t e FBI te esp ns ble f t e gency’s se f t ngR y nd t e cellular tracking technologies, we now know that t e R g den p sec t s’ eff ts to shield details about the StingRay were part of a coordinated effort across Federal, State and local agencies to keep law enforcement use of this equipment secret. pec f c lly, Agent M s n sse ts t t “disclosure of what appears to be innocuous information about the use of cell site simulators would provide adversaries with critical information . . . necessary to develop defensive technology, modify their behaviors an otherwise take countermeasures designed to thwart the se f t s tec n l gy.”167 Agent Morrison warns that “d scl s e . . . could result in t e FBI’s n b l ty t protect the public from terrorism and other criminal activity because, through public disclosures, this technology has been rendered essentially seless f f t e nvest g t ns.”168 Similar arguments have been made by a number of other local law enforcement agencies across the country.169 In order to ensure the continued effectiveness of cellular surveillance equipment, the FBI, for the past 10 years, has taken significant steps to protect information about the specific electronic equipment and techniques used by law enforcement from disclosure.170 These steps include what might be characterized as a purposeful lack of disclosure to magistrate judges when seeking approval to use a cell site simulator in a criminal investigation, strict non-disclosure agreements with state and local law enforcement and essentially across-the-board refusals to turn over documents relating to cell site simulators in response to FOIA and public records requests. This Part will describe the growth (one might even say the metastasis) of a discourse of secrecy regarding t e t ngR y’s use across various channels and levels of government. A. LACK OF DISCLOSURE AT THE FEDERAL MAGISTRATE LEVEL Despite the fact that US government agencies have used cellular interception devices for more than 20 years, the 2012 Judge Owsley opinion is one of only two known published magistrate opinions to address law enforcement use of this technology. There are several possible reasons for this dearth of judicial analysis,171 but one of the most troubling possibilities may be a lack of knowledge on the part of magistrate judges about the specific surveillance technique(s) they are authorizing, 166 Affidavit of FBI Supervisory Special Agent Bradley S. Morrison, Chief, Tracking Technology Unit, Operation Technology Division in Quanicio Division, April 11, 2014, tt c ent t C ty’s Ve f ed Answer, Beau Hodai v. City of Tucson, et al No. C20141225, April 14, 2014. 167 Id. at 1-2. 168 Id. at 2. 169 See discussion of local law enforcement agencies’ refusal to disclose on page 37. 170 Id. 171 For a broader discussion of the reasons underlying the lack of judicial review of law enforcement use of the StingRay, see Stephanie K. Pell & Christopher Soghoian, A Lot More Than A Pen Register, And Less Than a Wiretap: What the StingRay Teaches Us About How Congress Should Approach the Reform of Law Enforcement Surveillance Authorities, 16 Yale Journal of Law & Technology (forthcoming 2014).

33

due to a lack of candidly presented explanatory nf t n n t e g ve n ent’s applications. In one set of DOJ emails obtained by the ACLU through a Freedom of Information Act request, for example, a federal prosecutor in Northern California n ted t t “ ny gents e st ll s ng [cell l nte cept n tec n l gy w t ] pen register application [that] does not make [the use of that tec n l gy] expl c t.”172 Similarly, at a conference at Yale Law School in 2013, Judge Owsley observed that:

The practice of the feds’ not making clear the planned use of a StingRay when seeking surveillance authorization could be widespread. . . . I may have seen them before and not realized what it was, because what they do is present an application that looks essentially like a pen register application . . . . So any magistrate judge that is typically looking at a lot of pen register applications and not paying a lot of attention to the details may be signing an application that is authorizing a StingRay.173

That this information has not been made clear to judges appears not to be an unintentional oversight. In the Rigmaiden case,174 for example, prosecutors c nceded t t t e g ve n ent d n t de “f ll d scl s e t t e g st te judge [who issued the original order authorizing the surveillance] with respect to t e n t e nd pe t n f t e [ t ngR y] dev ce [ sed t l c te R g den].”175 The reason fo t t l ck f c nd , t e DOJ l te t ld t e c t, w s “because of the sensitive nature of the device in terms of concerns out of the disclosure to third parties.”176 A similar attempt to protect details about the use and functions of cellular interception technology appears to have occurred in a 2008 state case. Police in T ll ssee, Fl d l c ted v ct ’s st len p ne n t e defend nt’s p t ent.177

172 See email from Miranda Kane to USACAN-Attorneys-C n l, U. . Dep’t f J st ce (M y 23, 2011, 11:55 AM), https://www.aclu.org/files/assets/doj_emails_on_stingray_requests.pdf 173 Ryan Gallagher, Feds Accused of Hiding Information From Judges About Covert Cellphone Tracking Tool, Slate, Mar. 28, 2013, http://www.slate.com/blogs/future_tense/2013/03/28/StingRay_surveillance_technology_used_wit hout_proper_approval_report.html; see also Jennifer Valentino-Devries, 'Stingray' Phone Tracker Fuels Constitutional Clash, Wall St. J., Sept. 22, 2011, http://online.wsj.com/article/SB10001424053111904194604576583112723197574.html (reporting that when a prosecutor was asked by the judge how a court order or warrant could be bt ned w t t tell ng t e j dge w t tec n l gy w s be ng sed, t e p sec t esp nded “ t w s st nd d p ct ce, y n ”). 174 United States v. Rigmaiden, Case 2:08-cr-00814-DGC. See supra Part III.D for a more detailed discussion of the case. 175 United States v. Rigmaiden, Case 2:08-cr-00814-DGC. Id. T nsc pt f Defend nt R g den’s Motion to Suppress, DE 1004 at 81. 176 The DOJ prosecutor told t e c t t t “Obv sly, f t e g st te j dge d d q est ns, e w ld ve been ent tled t nswe s, s ny g st te”, b t w en sked by t e c t f t w s “t e magistrate's burden to ferret that out [information] while he's got the agents in h s ff ce,” t e prosecutor conceded that it was not. Id. at 81-82. 177 See Thomas v. State of Florida, No. 1D11-6156, District Court of Appeal of Florida, First District (Nov. 20, 2013).

34

While the specific name of the surveillance technology does not appear in the public court opinions or te ls, g ve n ent w tness test f ed t t “[ ]sing portable equipment we we e ble t … b s c lly stand at every door and every window in that complex and determine, with relative certainty … the particular area of the apartment that that [signals from the] handset [were] emanating from.”178 This description appears consistent with the capabilities of the StingRay family of products manufactured by the Harris Corporation.179 Facts in the Appellate Court opinion illustrate the various arguments and efforts of the Tallahassee Police Department to shield information about the cellular tracking dev ce. T e c t f st n tes t t t e p l ce “did not want to obtain a search warrant because they did not want to reveal information about the technology they used to track the cell phone signal.”180 In dd t n, “[ ]n investigator with the technical operations unit of the Tallahassee P l ce Dep t ent test f ed: ‘[W]e prefer that alternate legal methods be used, so that we do not have to rely upon the equipment to establish probable cause, just for not wanting to reveal the nature and et ds.”’181 T s w tness ls test f ed t t “‘[w]e have not obtained a search warrant [in any case], based solely on the equipment.’”182 At the Appellate oral argument, two of the judges, who had seen the still-sealed documents from the lower court, announced that the Tallahassee Police Department had used the same technology in two hundred cases without getting a warrant.183 Perhaps most nte est ng, weve , s t e p sec t ’s st te ent t t “there is a nondisclosure agreement that [the police have] g eed w t t e [ n f ct e ].”184 These statements are consistent with a broad effort to control the public disclosure of details pertaining to this cellular surveillance equipment. B. SECRECY VIA REGULATORY RESTRICTIONS AND NON-DISCLOSURE AGREEMENTS The Harris Corporation, which manufactures the StingRay, has submitted to the FCC applications for equipment authorization licenses for each of its cellular surveillance

178 Amended Initial Brief of Appellant at 9, Thomas v. State of Florida, Case no. 1D11-6156 (District Court of Appeal. First District of Florida). 179 See generally Ryan Gallagher, Meet the machines that steal your phone’s data, Ars Technica, September 25, 2013, http://arstechnica.com/tech-policy/2013/09/meet-the-machines-that-steal- your-phones-data/. 180 Thomas v. State of Florida, No. 1D11-6156, District Court of Appeal of Florida, First District (Nov. 20, 2013). 181 Id. 182 Id. 183 See Thomas v. State, No. 1D11-6156, Oral Arg. at 17:58, May 14, 2013, video available at http://oavideo.1dca.org/OAPlayer.aspx?ID=1416&CaseID=30919&File=116156.smil (Judge Makar st ted t t “t s ec d kes t ve y cle [t e T ll ssee P l ce Dep t ent] were not going to get a search warrant because they had never gotten a search warrant for this technol gy.” Moments later, J dge Bent n dded t t “200 t es t ey d n t” g tten w nt). 184 Thomas v. State of Florida, No. 1D11-6156, District Court of Appeal of Florida, First District (Nov. 20, 2013).

35

products.185 These applications include a request by Harris that the FCC impose specific conditions as part of eg l t y gency’s t z t n f H s’ surveillance equipment:

(1) The marketing and sale of these devices shall be limited to federal/state/local public safety and law enforcement officials only; and (2) State and local law enforcement agencies must [in] advance coordinate with the FBI the acquisition and use of the equipment authorized under this authorization.186

The FCC submissions filed by Harris go on to explain that the purpose of the requested license restrictions are to ensure that use of the product be “limited to its intended use, operated only by federal, state, and local public safety officials” and to “ dd ess c nce ns eg d ng t e p l fe t n f t e equipment to unauthorized se s.”187 The FBI and DOJ are indeed coordinating the use of this technology, particularly through use non-disclosure agreements, to limit disclosure to the public of information about cellular interception equipment. Special Agent Morrison acknowledges that the FBI has entered into non-disclosure agreements with state and local enforcement partners.188 He further claims that any information shared w t by t e fede l g ve n ent w t t e st te “c nce n ng cell site simulator technology is considered homeland security information under the Homeland ec ty Act.”189 The upshot of this classification is that cell site simulator nf t n “ e ns[s] nde t e c nt l f t e [FBI].”190

185 See Tania W. Hanna and Evan S. Morris, Final Request for Confidentiality of Harris Corporation for FCC ID No. NK73092523 (FCC Correspondence Number 39487), Submission to the Federal Communications Commission, April 28, 2011, archived copy available at http://files.cloudprivacy.net/Harris-FCC-confidential-request-1.pdf. See also Tania W. Hanna and Evan S. Morris, Final Request for Confidentiality of Harris Corporation for FCC ID No. NK73186795 (FCC Correspondence Number 39483), Submission to the Federal Communications Commission, March 21, 2011, archived copy available at http://files.cloudprivacy.net/Harris-FCC- confidential-request-2.pdf 186 Id at 2. 187 Id. 188 Morrison Affidavit, supra note ** at 2. 189 Id. t 3 (expl n ng t t “[t] e Act def nes el nd sec ty nf t n s nf t n t t relates to the ability to prevent, interdict or disrupt terrorist activity; information that would improve the identification or investigation of a suspected terrorist or terrorist organization; or nf t n t t w ld p ve t e esp nse t te st ct” citing 6 U.S.C. §§ 482(f)(1)(B)-(D) nd sse t ng t t “[c]ell s te s l t tec n l gy eets ll t ee c te .” Id. 190 Id. citing 6 U.S.C. §482(e) (“ el nd sec ty nf t n ‘ bt ned by t te l c l government form a Federal agency under this section shall remain under the control of the Federal agency, and a State or law authorizing or requiring such a government to disclose information shall n t pply t s c nf t n.’”) Id.

36

Local law enforcement agencies that have purchased Harris cellular interception technology have referenced signing Non-Disclosure Agreements with both the DOJ191 and the manufacturer of the equipment.192 The Harris non-disclosure agreement, which has been obtained by activists through open records act requests,193 specifically prohibits the disclosure of any information about the use of t e c p ny’s p d cts including operations, missions and investigative results t t w ld be dee ed “ ele se f tec n c l d t .”194 C. FEDERAL FOIA AND STATE PUBLIC RECORDS ACT RESPONSES Over the past few years, privacy advocates and journalists have submitted numerous open records requests to federal and state law enforcement agencies seeking any documents pertaining to StingRays and related surveillance technologies.195 The FBI, DOJ and DHS have, collectively, located more than 26,000 relevant documents,196 but have either withheld them in their entirety or released 191 See Detective Jeffrey Shipp, City of Tacoma Police Department, Memo to Kathy Katterhagen, March 3, 2013, http://cms.cityoftacoma.org/cityclerk/Files/CityCouncil/RecentLegislation/2013/RL20130319.pdf at 21(“T e c ent H s C p t n tec n l gy wned by [T c P l ce Dep t ent] w s received through a Department of Justice (DOl) Law Enforcement Grant Award in 2007 with a c nt ct l w nty nd p p et y NDA s gned pe DOJ eq e ents…. A c nt ct l w nty and support for current technologies owned by [Tacoma Police Department] remains in effect. A new NDA with the DO] has been approved for the new technologies awarded in the grant.”). 192 See Thomas v. State of Florida, No. 1D11-6156, District Court of Appeal of Florida, First District (Nov. 20, 2013). See also Jennifer Portman, FDLE signed Stingray non-disclosure deal, Tallahassee Democrat, March 30, 2014, http://www.tallahassee.com/article/20140330/NEWS01/303300011/FDLE-signed-Stingray-non- disclosure-deal (“FDLE Commissioner Gerald Bailey said his agency had a non-disclosure agreement with the FBI to not reveal information about the technology, but did not have one with Harris Corp”). See also FBI FOIA documents provided to the Electronic Privacy Information Center, April 30, 2013, http://epic.org/foia/fbi/stingray/FBI-FOIA-Release-04302013-s1-OCR.pdf at 27 (“Consistent with the conditions on the equipment [redacted] must coordinate with the Federal Bureau of Investigation (FBI) to complete this non-d scl s e g ee ent.”). 193 See Non Disclosure Agreement, Wireless Products Group, Harris Corporation, June 7, 2010, page 19 of http://www.wired.com/images_blogs/threatlevel/2014/03/ACLU-Stingray-Complaint-Hodai- v-TPD.pdf 194 Id. at 10. 195 See EPIC v. FBI – Stingray/Cell Site Simulator, Electronic Privacy Information Center, https://epic.org/foia/fbi/stingray/ (collecting documents released by Department of J st ce el t ng t FBI’s se f cell s te s l t s). See also Nathan Freed Wessler, Police Hide Use of Cell Phone Tracker From Courts Because Manufacturer Asked, ACLU Free Future Blog, March 3, 2014, https://www.aclu.org/blog/national-security-technology-and-liberty/police-hide-use-cell- phone-tracker-courts-because (“So the ACLU and ACLU of Florida have teamed up … submitting p bl c ec ds eq ests t ne ly 30 p l ce nd s e ffs’ dep t ents c ss Florida seeking information about their acquisition and use of stingrays.”). 196 See Kenneth Courter, Acting Chief, FOIA/PA Unit, Criminal Division, Department of Justice, Letter to Christopher Soghoian, July 27, 2013 http://www.cloudprivacy.net/DOJ-Stingray-FOIA-5th- reply.pdf at 1 ("As to the portion of your request for information concerning cell site simulators, digital analyzers, and similar mobile phone surveillance technology generally, the Criminal Division possessed an additional five hundred and sixty-seven pages of responsive records, and has determined that these records are exempt from disclosure"). See also Tony R. Tucker, FOIA Officer,

37

them in such a heavily-redacted form that they reveal little to no useful information.197 To justify their limited disclosure, the FBI, DOJ, and DHS claim a number of FOIA exemptions, including arguments that the production of documents would: (1) reveal classified information; (2) disclose techniques and procedures for law enforcement investigation; and (3) could reasonably be expected to risk circumvention of the law.198 C ns stent w t t e g ve n ent’s FOIA p s t ns, the p sec t n t e R g den c se st ted t t “t e sens t ve n t e f t e eq p ent [used to locate the defendant] goes beyond issues of law enforcement to matters of national security,” s “s e f t s eq p ent s n t nly sed n t e l w enf ce ent e l , t's sed n t e n t n l sec ty e l .”199 Local law enforcement agencies have similarly been evasive. In response to queries from journalists working with USA Today, thirty-six police agencies refused to confirm whether or not they have even used cellular surveillance equipment.200 Several state and local law enforcement agencies have also refused to disclose records related to the use of this technology, arguing that “criminals or terrorists could use the information to thwart important crime-fighting and surveillance techniques.”201 In sum, these federal and state responses, while perhaps lawful responses to FOIA and Public Records Act requests, illustrate a much larger secrecy policy and narrative: law enforcement agencies believe that the existence, capabilities and limitations of this cellular interception technology are secret and that the secrecy must persist in order to for the technology to continue to be an effective law enforcement surveillance tool.202 Office of Intelligence and Analysis, Department of Homeland Security, Letter to Christopher Soghoian, February 17, 2012, http://files.cloudprivacy.net/DHS-OIA-Stingray-FOIA-reply.pdf t 2 (“the Office of Intelligence and Analysis located 1085 pages. Of these total pages, 1046 must be withheld in their ent ety.”) See also Fourth Declaration of David Hardy, in EPIC v. FBI, Oct 1, 2013, https://epic.org/foia/fbi/stingray/Fourth-Hardy-Declaration.pdf, t 9, (“The FBI reviewed and processed a total of 22,982 pages of responsive material, of which, 4,377 pages were released in full or in part, and 18,605 were withheld in full.”). 197 The FBI, DOJ, and DHS cited a number of FOIA exemptions to support withholding of documents or redacting information contained on the documents, including that the production of documents would: (1) reveal classified information; (2) disclose techniques and procedures for law enforcement investigation; and (3) could reasonably be expected to risk circumvention of the law. Id. 198 Id. 199 United States v. Rigmaiden, Case 2:08-cr-00814-DGC, DE 451 at 14. 200 See John Kelly, Cellphone data spying: It's not just the NSA, USA Today, December 8, 2013, available at http://www.usatoday.com/story/news/nation/2013/12/08/cellphone-data-spying-nsa- police/3902809/ 201 Id. 202 See Nathan Freed Wessler, L c l P l ce n Fl d Act ng L ke T ey’ e t e CIA (B t T ey’ e N t), ACLU Free Future Blog, March 25, 2014, https://www.aclu.org/blog/national-security-technology- and-liberty/local-police-florida-acting-theyre-cia-theyre-not (desc b ng “Gl ” esp nse f the Sunrise, Florida Police Department, neither conforming nor denying the existence of documents related to the purchase of Harris cellular surveillance technology). See also Taylor Killough, State Police Acknowledge Use Of Cell Phone Tracking Device, Indiana Public Media, December 12, 2013, http://indianapublicmedia.org/news/state-police-respond-investigation-tracking-device-59918/

38

V. A SECRET NO MORE While US government agencies shroud cellular interception technology in secrecy, in several other countries this same technology is subject to legislative oversight, judicial review and, thus, public discourse. In still other countries, the unregulated nature of this technology has led to a chaotic situation where thousands of untracked interception devices are in use, many by non-governmental actors. Moreover, skilled hobbyists using readily available off-the-shelf components can now build homemade cellular interception devices for a tiny fraction of the cost law enforcement and security agencies pay for H s’ t ngR y. In, among other things, detailing the existence of an open, global market for cellular interception technology, this Part will dispel any rational notion that cellular interception technology is or can be kept secret. A. THE GLOBALIZATION OF CELLULAR INTERCEPTION TECHNOLOGY The first generation of cellular interception technology was introduced during the early-1990s. Generally, it was expensive and sold by a few defense contractors only to major global powers. Today, however, both passive and active surveillance devices are much cheaper and available on the open market from surveillance vendors in the Middle East, South America and Asia. The major powers thus no longer enjoy a monopoly over cellular phone surveillance. It has become, for better or for worse, irreversibly globalized. The first phone interception devices were sold by defense contractors to major global powers such as Germany,203 the United Kingdom,204 the United States, and most likely, Russia and Israel.205 Over the past three decades, the market for this

(“Indiana State Police Captain Dave Bursten said in a statement the department is working well w t n t e b nds f t e l w.…B sten w n’t s y ex ctly w t e [StingRay] technology is used, beca se e s ys t w ld be ‘like a football te g v ng p t e pl yb k.’”). 203 See supra note 57. 204 See MMI Research Ltd v Cellxion Ltd & Ors [2009] EWHC 418 (Pat) (11 March 2009) available at http://www.bailii.org/ew/cases/EWHC/Patents/2009/418.html (describing the demonstration of the GSM-X interception device to potential government clients in 1999 by MMI Research Ltd, a British surveillance equipment manufacturer). 205 Given the active, sophisticated espionage efforts of the Russian and Israeli intelligence agencies, it is almost certainly the case that companies in these countries were early manufacturers of this technology too. Today, there are many, large companies in Israel and Russia that actively export cellular surveillance equipment around the world. See Cellular Interception, Ability Computers & Software Industries Ltd (Israel), available at http://www.interceptors.com/intercept- solutions/Cellular-Interception.html. See also Septier Guardian Tactical Systems (Israel), http://www.septier.com/93.html (describing several cellular surveillance products.). See also Andrei Soldatov and Irina Borogan, 5 Russian-Made Surveillance Technologies Used in the West, Danger Room, May 10, 2013, http://www.wired.com/dangerroom/2013/05/russian-surveillance- tec n l g es/ (“[T e] D sc ve y Telec Tec n l g es (DTT) … AIBI syste ( In-Between Interception System) works by masquerading as a cell phone tower, sucking in nearby signals and ll w ng t e dev ce’s pe t t s ept t sly l sten nd ec d. Est bl s ed n M sc w, t e f

39

technology has steadily expanded and the price of the technology has, consequently, dropped. Manufacturers and resellers now include firms in Argentina,206 Bangladesh,207 Canada,208 China, India,209 Malaysia,210 the Netherlands,211 Pakistan,212 Switzerland,213 and Taiwan,214 and Turkey,215 who, in addition to selling devices to their own governments, actively seek out other government (and, perhaps non-government) customers as part of the five billion dollar global market for commercial surveillance technology.216 Indeed, cellular interception devices are ep tedly ng t e “bestsell ng te s” ex b ted t s ve ll nce nd st y t de shows.217 Although several governments have employed phone interception technology, the extent to which it has been used responsibly and disclosed to the public varies

also counts offices in Switzerland and Salt Lake City, Utah, and boasts on its Russian website about including the Kremlin and t e F B ng ts cl ents.”). 206 See Soluciones para gobierno (Argentina), http://solucionesparagobierno.com/english/productos.html 207 Ezzy Ente p se, L st ng n Al B b f “P ss ve G M (D l B nd) / CDMA M n t ng yste ,” http://www.alibaba.com/product-detail/Passive-GSM-Dual-Band-CDMA- Monitoring_103809673.html. 208 GSS Pro-A GSM Interceptor, Global Security Solutions (Canada), available at http://www.global- security-solutions.com/ProAInterceptor.html. 209 See Shoghi Communications Ltd. (India), http://www.shoghicom.com/cellular-monitoring.php (describing the cellular intercept products available for sale). See also 8th Angle System, Listing for “IM I C tc e ,” http://www.tradeim.com/company.html?method=product&productCode=8693695. 210 See GSM Interceptors, Infra Langit (Malaysia), available at http://infralangit.com/gsm- interceptors/. 211 See GSM Interception System, PI Products (Netherlands), http://www.pi-products.nl/pi- products/PDF/Communication%20Monitoring/Monitoring%20GSM%20networks/gsm%20intercep tion%20system.pdf. 212 See GSM interceptor Scanner, listed for sale at AliBaba by the Fusions Group, Karachi, Pakistan, available at http://www.alibaba.com/product-free/127063152/GSM_interceptor_Scanner.html. 213 See Product catalog for Neosoft AG (Zurich, Switzerland), https://www.documentcloud.org/documents/810502-945-neosoft-catalogue.html 214 See M k L z te (T w n), l st ng f “IM I C tc e ”, http://www.alibaba.com/product- detail/IMSI-catcher_135958750.html (l st ng t e PKI 1640 f $1800 pe n t, w c c n “catch all active UMTS mobile phones in your proximity. All captured data, such as IMSI, IMEI, TMSI will be stored in the data base and are available for further evaluation at any time.”) 215 See Muhendis E Mutlu (Ank , T key), L st ng n Al B b f “interceptor gsm A5-1 A5-2 ve 3,” http://www.alibaba.com/product-free/126383443/interceptor_gsm_A5_1_A5_2.html. 216 See Nicole Perlroth, Software Meant to Fight Crime Is Used to Spy on Dissidents, New York Times, August 30, 2012, available at http://www.nytimes.com/2012/08/31/technology/finspy-software-is-tracking-political- dissidents.html (“T e ket f s c tec n l g es s g wn t $5 b ll n ye f ‘n t ng 10 ye s g ,’ s d Je y L c s, p es dent f Tele t teg es, t e c p ny be nd I W ld, n nnual s ve ll nce s w.”) 217 See Stefan Krempl, 28C3: New attacks on GSM mobiles and security measures shown, The H Open, December 28, 2011, available at http://www.h-online.com/open/news/item/28C3-New-attacks-on- GSM-mobiles-and-security-measures-shown-1401668. t l (“F ll w ng t p e l e t s ye t t e Mecca of the "cyber-industrial complex", the Intelligent Support Systems (ISS) trade fair which is held at various sites in Asia and the Middle East, Nohl reports that the bestselling items in the espion ge c n ty t p esent e dev ces f n t ng b le p nes, s c s IM I c tc e s.”)

40

considerably by country. Germany is perhaps the most open and transparent country regarding its use of active interception technology. The use of such devices by German government agencies is specifically regulated by several statutes,218 which mandate, among other things, that statistical data describing their use be aggregated and published by the German Parliament.219 Moreover, there have been several formal parliamentary questions submitted regarding the use of IMSI catchers,220 as well as a decision from the German Constitutional Court permitting their use.221 It is in India, however, where cell phone interception technology has had the most high profile and politically destabilizing impact. Beginning in 2005, agencies in the Indian national government imported passive cellular interception systems.222 In 2010, d ec d ngs nd w tten t nsc pts f p l t c ns’ c lls that were intercepted with these devices were leaked to the press, leading to a huge scandal.223 Media reports revealed that just two years after the devices were first purchased by the national intelligence agency, they were used to monitor the phone calls of senior politicians, including opposition-leaders.224

218 See Section 9 of the Federal Constitution Protection Act (Special Forms of Data Collection): http://www.gesetze-im-internet.de/bverfschg/__9.html, paragraph 4. See generally Chapter on German interception law by Rau in http://books.google.com/books?id=GNCpeUdVkOoC&lpg=PA654&pg=PA349#v=snippet&q=IMSI&f= false 219 http://dip21.bundestag.de/dip21/btd/17/127/1712774.pdf (2011 data) http://dipbt.bundestag.de/dip21/btd/17/086/1708638.pdf (2010 data) 220 http://dip21.bundestag.de/dip21/btd/14/068/1406885.pdf (2001) http://dipbt.bundestag.de/dip21/btd/17/076/1707652.pdf (2011) 221 See http://www.akvorrat.at/sites/default/files/VDS_Materialien/Art%2029%20WP%2010th_annual_re port_en.pdf (An English language summary of the ruling by the Federal Constitutional Court on 22 August 2006 on the use of the IMSI-catchers in criminal proceedings. See also http://www.bundesverfassungsgericht.de/entscheidungen/rk20060822_2bvr134503.html (the decision of the court, in German) 222 See Saikat Datta, A Fox On A Fishing Expedition, Outlook India, May 3, 2010, available at ttp://www. tl k nd .c / t cle. spx?265192 (“Ind beg n p c s ng t e ff-the-air GSM/CDMA monitoring systems around 2005-06, and the first interception of a mobile phone conversation using the system was carried out by the NTRO on January 7, 2006, in New Delhi. Then National Security Advisor (NSA) M.K. Narayanan was visiting the facility when the interception capability of the device was demonstrated to him. The NSA made a call to his office, which was s ccessf lly t pped nd c plete t nsc pt f s c ll p v ded t w t n n tes f t e c ll.”). See also Harish Gupta and Nivedita Mookerji, Private hand in phone tapping worries Manmohan Singh; probe ordered, DNA, December 14, 2010, available at http://www.dnaindia.com/india/1481036/report-private-hand-in-phone-tapping-worries- manmohan-singh-probe- de ed (“T ese c nes we e f st nt d ced n t e NTRO, t p government tec n c l s ve ll nce gency d ectly nde t e PM, s et e n 2005.”) 223 See Saikat Datta, Bootleg Tapes: The Rulers Who Listen, Outlook India, May 10, 2010, available at http://www.outlookindia.com/story.aspx?sid=4&aid=265272 (describing various conversations recorded using the surveillance technology and provided to the press). 224 See Saikat Datta, We, The Eavesdropped, Outlook India, May 3, 2010, available at http://www.outlookindia.com/article.aspx?265191 (describing the interception by the NTRO of politicians)

41

An anonymous intelligence official told one Indian newspaper that cellular interception technology enabled t e t “d g nt eve y ne’s l fe, be t p l t c l nd corporate leaders, journalists, social activists or bureaucrats. We can track anyone we c se.”225 Another anonymous official stressed that a principal strategic advantage of the technology s t t t “w ks n den b l ty . . . It c n be depl yed nyw e e. We d n’t need t s w ny [formal legal] t z t n s nce we’ e n t tapping a phone number at the [w eless c e ’s ff ce] b t nte cept ng s gn ls between the phone and the cellphone tower and recording them on a hard disk. If too many questions are asked, we can remove the disk and erase the conversation. N ne gets t kn w.”226 In addition to the widespread use of the devices against politicians, news reports also reveal that the equipment has been used to spy on the calls of top business leaders and movie stars. A senior police officer framed the problem for one j n l st n t ese te s: “W en n ff ce n s l y f [150 d ll s] nt s pretty much unrestricted access to this kind of technology, things will go wrong, and ve g ne w ng.”227 A subsequent official investigation revealed that lax customs rules permitted unregulated importation and purchase of the interception technology. Government officials later acknowledged over forty different makes and models of cellular interception technology had been imported from dozens of vendors.228 The devices had been purchased by numerous agencies in the national government, the military229 and state governments, as well.230 Officials estimate that thousands of cellular interception devices have been imported,231 and that hundreds

225 See Datta (Fox on a Fishing Expedition), supra note **. 226 See Datta (We, The Eavesdropped), supra note **. 227 See Praveen Swami, The government's listening to us, December 1, 2011, available at http://www.thehindu.com/news/national/the-governments-listening-to-us/article2678501.ece 228 See Sudhi San, Phone-tapping: Telecom firms under scanner for eavesdropping?, NDTV, September 25, 2012, available at http://www.ndtv.com/article/india/phone-tapping-telecom-firms-under- scanner-for-eavesdropping-271661 (“B t t e b d news s, f t e 45-odd suspected machines dent f ed, t e g ve n ent d esn't ve t e dd ess f p te s f s ny s 24 c nes.”). See also Sanjay Singh, Government hunts for elusive bug: DoT wants snooping and listening devices within private sector surrendered, Mail Online India, November 28, 2012, available at http://www.dailymail.co.uk/indiahome/indianews/article-2239422/Government-hunts-elusive- bug-DoT-wants-snooping-listening-devices-private-sector-s ende ed. t l (“Desp te the ban on the free import of phone interceptors, these gadgets manufactured in Israel, the UK, France and China continue to be smuggled into the country through Nepal and Bangladesh. It is believed that there as many as 45 different variants of these m c nes dev ces fl t ng nd n Ind .”) 229 See Ritu Sarin, MHA poses fresh queries about Army interceptors, The Indian Express, November 4, 2012, available at http://www.indianexpress.com/news/mha-poses-fresh-queries-about-army- interceptors/1026444/ (describing the use of off the air intercept equipment by the army) 230 See Hitender Rao, ‘Off-air’ tapping: MHA wants states to surrender devices, Hindustan Times, June 9, 2011, available at http://www.hindustantimes.com/Punjab/Chandigarh/Off-air-tapping-MHA- wants-states-to-surrender-devices/Article1-715297.aspx (describing their use by the state of Haryana) 231 See 'Invisible' phone taps: Is the Govt worried?, NDTV, March 02, 2012, available at http://www.ndtv.com/article/india/invisible-phone-taps-is-the-govt-worried-181763 (“My inquiries with the government authorities have revealed that during the last three years, 1100 GSM

42

are in the possession of private parties, such as corporations and detective agencies.232 By late 2010, senior Indian government officials acknowledged that legal prohibitions on the private purchase and use of cellular interception technology w ld n t p tect t e p v cy f c t zens’ c n c t ns. Ind ’s p e n ste st essed t e need t “l k f s l t ns t g tec n l gy t p event ccess of telep ne c nve s t ns.”233 Another senior government official acknowledged that the secrecy of government communications was threatened by the private use of interception technology.234 B. THE DEMOCRATIZATION OF CELLULAR INTERCEPTION TECHNOLOGY The effective monopoly over cellular interception technology long enjoyed by governments was largely due to the cost.235 The retail price for each device was somewhere between $50,000 and $400,000,236 depending on the features—far too expensive for the average person, but a relatively small sum for the military,

n t ng nte cept s we e p ted”) See also Ritu Sarin, States begin to surrender off-air phone snooping equipment, The Financial Express, June 5, 2012, available at http://www.financialexpress.com/news/states-begin-to-surrender-offair-phone-snooping- equipment/957859 (stating that 73,000 devices had been imported, although some of these were dual use.) 232 See Singh, Government hunts for elusive bugs, supra note ** (stating that 2000 off the air surveillance devices are estimated to have been imported). See also NDTV (invisible phone taps), supra n te ** (“ ces n t e Telec Dep t ent nd H e M n st y s spect t t ng t e buyers are large corporate houses, politically-aligned detective agencies and even government genc es w e n t t zed (s c) t c y t cellp ne t ps.”) 233 See Manoj Mitta, Off-the-air taps a bigger worry: PM, The Times of India, December 15, 2010, available at http://articles.timesofindia.indiatimes.com/2010-12-15/india/28230420_1_cabinet- secretary-telephone-interception-national-technical-research- g n z t n (“ ng st essed t e need t ‘l k f s l t ns t g tec n l gy t p event ccess f telephone conversations to systems ts de t e nst t t n l f ew k f g ve n ent’”) 234 See Singh (Government hunts for elusive bugs), supra ** ("A top government official, who did not want to be named, said a large number of corporate houses have small offices in and around central Del e s n t e p x ty f p t nt g ve n ent b ld ngs. ‘Off c ls w k ng n key p s t ns nde v s n st es nd sens t ve dep t ents e, t e ef e, v lne ble t p ne t pp ng,’ e pointed out, suggesting that t ese ff ces c n f nct n s b ses f t e sn p ng pe t ns.”) 235 See Ralf-Philipp Weinmann, Baseband Attacks: Remote Exploitation of Memory Corruptions in Cellular Protocol https://www.usenix.org/system/files/conference/woot12/woot12-final24.pdf Stacks, 6th U ENIX W ks p n Offens ve Tec n l g es, A g st 6, 2012, v l ble t (“In t e p st, sp fing G M netw k eq ed s gn f c nt nvest ent, w c l ted t e set f p ss ble attackers. . . Open-source solutions such as OpenBTS allow anyone to run their own GSM network at a fraction of the cost of carrier-grade equipment, using a simple and cheap software-defined d . T s devel p ent s de G M sec ty expl t ns p ss ble f s gn fic ntly l ge set f sec ty ese c e s.”) 236 See John Kelly, Cellphone data spying: It's not just the NSA, USA Today, December 8, 2013, available at http://www.usatoday.com/story/news/nation/2013/12/08/cellphone-data-spying- nsa-p l ce/3902809/ (“T e cell-tracking systems cost as much as $400,000, depending on when they were bought and what add-ons they have. The latest upgrade, code-n ed ‘H lst ,’ s sp ng w ve f pg de eq ests.”)

43

intelligence community and even many law enforcement agencies. Part of the high price reflected the difficulty and significant capital investment required to design and manufacture the StingR y’s sophisticated radio equipment. As a result, hobbyists and researchers without large budgets were simply unable to develop cellular communications technology. This cost barrier no longer exists. Moreover, a set of free software tools has been developed by a community of researchers and hobbyists that has lowered the skill-level necessary to tinker with cellular communication technology. Consequently, as the cost and ease of developing cellular interception technology has declined, the longstanding nation-state monopoly has vanished. Surveillance has become democratized and, correspondingly, the motives for surveillance have multiplied. The next elements of this Part will describe briefly how innovations in radio technology have enabled researchers and hobbyists without large budgets to develop their own cellular interception devices. 1. LOW COST SOFTWARE-DEFINED RADIO BASED ACTIVE INTERCEPTION Hobbyists can now build their own active surveillance devices with readily available electronic components currently costing approximately $700. The ability to create such low-cost cellular interception devices is due to technological innovations that have lowered both the costs and skill-level necessary to develop radio technology. Specifically, a revolution in software-defined radio technology during the past decade has eliminated the longstanding technical barriers that prevented researchers and hobbyists from being able to experiment freely with large swaths of the radio spectrum. Software-defined radios are flexible hardware platforms that, when combined with specific software, “can change the frequency range, modulation type or output power of a radio device without making changes to hardware components.”237 Instead of having to create expensive new microchips (i.e. hardware) for each new radio technology—such as GPS navigation, Bluetooth, and High Definition TV—a low cost software-defined radio, combined with specific software for a particular application, can now be used instead. The development of software-defined radio has reduced earlier barriers of access to radio technology, thus enabling tinkering by researchers of varied skill-levels. This access has allowed developers to create, for example, free software capable of operating a cellular network. Indeed, OpenBTS is a popular open source, cellular base station software suite,238 which is designed to work with low cost (currently

237 See FCC Approves First Software Defined Radio, Federal Communications Commission, Press Release, November 19, 2004, http://hraunfoss.fcc.gov/edocs_public/attachmatch/DOC- 254463A1.doc 238 See Harvind Samra, The OpenBTS project - an open-source GSM basestation using the USRP and VoIP, message posted to GNURadio mailing list, September 3, 2008, available at http://lwn.net/Articles/296949/

44

$700) software-defined radios.239 The existence of OpenBTS and similar software has thus significantly reduced the cost of creating and running a cellular network and brought it within the reach of non-profit organizations, rural communities and hobbyists.240 Once hobbyists and researchers were able to build and operate their own cellular networks with open source software, it was only a matter of time before the software was modified such that it could masquerade as a legitimate wireless carrier’s netw k with the capacity to intercept calls.241 Indeed, a security researcher did just that in 2010—in front of an audience at the DEF CON security conference—using a laptop running OpenBTS that had been configured to sq e de s AT&T’s netw k, thereby allowing the researcher to intercept outgoing calls from the phones of audience members.242 Although the hardware and software necessary to build an OpenBTS-based cellular interception device is readily available, doing so still takes a significant amount of technical expertise. As is often the case with difficult-to-exploit security vulnerabilities, however, the usability barriers eventually shrink with the development of easy-to-use software.243 Once these usability barriers are removed,

239 See generally Taylor Killian, SDR Showdown: HackRF vs. bladeRF vs. USRP, August 7, 2013, available at http://www.taylorkillian.com/2013/08/sdr-showdown-hackrf-vs-bladerf-vs-usrp.html (comparing various software-defined radios). 240 Volunteers using OpenBTS have operated free cellular networks at Burning Man, a popular festival held in the Nevada desert, as well as at several computer security conferences. See generally Davis Burgess, Burning Man 2011 - Yes we were there, The OpenBTS Chronicles, September 6, 2011, available at http://openbts.blogspot.com/2011/09/burning-man-2011-yes-we-were-there.html. See also Dan Goodin, At Defcon, hackers get their own private cell network: Ninja Tel, Ars Technica, July 28, 2012, available at http://arstechnica.com/security/2012/07/ninja-tel-hacker-phone-network/. Non-profit organizations have also used OpenBTS to provide cellular service to remote communities in developing countries. See Stephen Lawson, Cell system used in Antarctica may help to cover the Plains, Computer World, 26 March, 2013, available at http://www.computerworld.com.au/article/457350/cell_system_used_antarctica_may_help_cover_p l ns/ (“One f [t e OpenBT ] netw ks se ves e te v ll ge n P p , Ind nes , t t c n nly reach the outside world via satellite. Residents of the village can now call and text each other and exchange text messages with the rest of the world using an OpenBTS network linked to a satellite t nsce ve .”) See also Jacqueline Mpala and Gertjan van Stam, Open BTS, a GSM experiment in rural Zambia, The Fourth International IEEE EAI Conference on e‐Infrastructure and e‐Services for Devel p ng C nt es (AFRICOMM’12), N ve be 2012, v l ble t http://www.academia.edu/2122498/Open_BTS_a_GSM_experiment_in_rural_Zambia. 241 David Burgess, the co-creator of OpenBTS who has previously written software for commercial IM I c tc e s s bse ved t t “Ne ly ny BT [(b se t nsce ve st t n)] BT s l t c n be used as the basis of an IMSI-c tc e .” See David Burgess, Some Comments on IMSI Catchers, The OpenBTS Chronicles, May 6, 2009, http://openbts.blogspot.com/2009/04/someLcommentsLonLimsiLcatchers.html. 242 See Chris Paget, Practical Cellphone Spying, Defcon 18, July 31, 2010, video at 23:36, available at http://www.youtube.com/watch?v=DU8hg4FTm0g. 243 See Paul Ohm, The Myth of the Superuser, Fear, Risk, and Harm Online, UC Davis Law Review Vol. 41, N . 4, P ge 1327, Ap l 2008 , t p ge 1399 (“ et es pe se s e p we d n y se s with easy-to- se [ ck ng] s ftw e.”). See also Kate Murphy, New Hacking Tools Pose Bigger Threats

45

low-cost interception tools will be available to anyone with a motive or interest in listening to the calls of others.244 2. LOWER COST ACTIVE INTERCEPTION WITH FEMTOCELLS Technically skilled hobbyists and researchers can create even cheaper, more organic active interception technology using a femtocell, a device that extends t e c e ’s own network. More specifically, in order to provide better cellular service to their cust e s nd t f ll n “de d sp ts” w e e t e e s p ecept n, wireless providers have, in recent years, augmented their networks with devices known as microcells, picocells and femtocells.245 These small cellular base stations, which customers can install in their homes or offices, provide cellular connectivity to nearby phones within tens or hundreds of meters.246 Indeed, these devices are already widely deployed in the US—Sprint and AT&T each has distributed more than 1 million femtocells.247 From the perspective of a cellular phone, a femtocell is a normal cellular base st t n, nd st ng s ble f c e ’s b se st t n nst lled t cell tower. Bec se t ey st be nst lled n c ns e s’ es, the devices, unlike traditional cell towers, are small, easy to use and inexpensive. They are typically sold for less than $100248 and often given away for free to consumers who complain about poor

to Wi-Fi Users, New York Times, February 16, 2011, available at ttp://www.nyt es.c /2011/02/17/tec n l gy/pe s n ltec /17b s cs. t l (“Unt l ecently, only determined and knowledgeable hackers with fancy tools and lots of time on their hands could spy while you used your laptop or smartphone at Wi-Fi hot spots. But a free program called F es eep … s de t s ple t see w t t e se s f n nsec ed W -Fi network are doing and t en l g n s t e t t e s tes t ey v s ted.”) 244 For example, one German graduate student created a more usable IMSI catcher based on OpenBTS for his ste ’s thesis. See Dennis Wehrle, Open Source IMSI-Catcher, University of Freiburg, October 28, 2009, archived copy available at https://github.com/tom-mayer/imsi-catcher- detection/blob/master/Papers/Thesis%20KS/Ausarbeitung-Dennis_Wehrle.pdf 245 Femtocells, picocells, and femtocells all employ the same underlying technology. The difference between these products is their effective range. Microcells, picocells, and femtocells provide service to areas of 200m-2km, 4m-200m and 10m, respectively. See Dimitris Mavrakis, Do we really need femtocells?, VisionMobile Blog, December 1, 2007, available at http://www.visionmobile.com/blog/2007/12/do-we-really-need-femto-cells/ 246 See Id. 247 See e M ek, p nt’s fe t cell t lly t ps 1M, F e ce W eless, Oct. 24, 2012, v l ble t http://www.fiercewireless.com/story/sprints-femtocell-tally-tops-1m/2012-10-24. See also Informa, Small Cell Market Status, February 2013, available at http://www.smallcellforum.org/smallcellforum_resources/pdfsend01.php?file=050-SCF_2013Q1- market-status%20report.pdf, p ge 3 (“ p nt’s depl y ent e c ed 1 ll n n ts s f Oct be 2012 nd n lysts est te t t AT&T’s depl y ent s e c ed s l n be s.”) 248 See Roger Cheng, A Cell Tower of Your very Own, The Wall Street Journal, July 8, 2010, available at http:// nl ne.wsj.c / t cle/ B10001424052748703636404575353153350315146. t l (“AT&T has been rolling out the 3G Microcell, which provides a full signal to a surrounding area of up to 5,000 square feet, as an answer for customers in areas with poor reception. The price is $149.99. Ve z n W eless's fe t cell, t e ‘Netw k Extende ,’ s p ced t $99.99.”)

46

service.249 The femtocell was, therefore, a naturally attractive target for security researchers.250 The devices are widely available and affordable, yet as fully functional cellular base stations, have the capability to deliver (and intercept) calls, text messages and data connections. Moreover, the femtocells—like any computer— have security flaws that researchers have been able to exploit to gain administrative access. Indeed, researchers have then been able to modify the devices, turning the femtocells into hundred dollar surveillance devices capable of intercepting communications to and from nearby phones.251 While the degree of technical skill necessary to turn a femtocell into an interception device is high,252 their low cost and small size makes them an ideal choice for a technically sophisticated criminal. 3. ADVANCES IN PASSIVE INTERCEPTION Just as the software-defined radio revolution and the availability of open source cellular radio software have lowered the cost of active interception, they have also enabled researchers and hobbyists to create low-cost, passive interception devices. Such capacity to receive the signals transmitted over the air between phones and cellular networks should not automatically enable interception of the contents of telephone calls. After all, modern cellular networks generally use encryption technologies to protect communications.253 The wireless industry, however, 249 See generally Eric Savitz, Sprint Giving Femtocells To Some Customers; Will VZ, T Follow?, B n’s, ept 15, 2010, v l ble t http://blogs.barrons.com/techtraderdaily/2010/09/15/sprint-giving-femtocells-to-some- customers-will-vz-t-follow/ 250 See generally Ravishankar Borgaonkar, Kevin Redon, and Jean-Pierre Seifert, Security analysis of a femtocell device, In Proceedings of the 4th international conference on Security of information and networks (SIN '11), 2011 ACM, New York, NY, USA, 95-102. See also Nico Golde, Kevin Redon and Ravishankar Borgaonkar, Weaponizing Femtocells: The Effect of Rogue Devices on Mobile Telecommunications, In the Proceedings of the 19th Annual Network and Distributed System Security Symposium, (NDSS 2012), San Diego, February 2012. See also David Malone, Darren F Kavanagh and Niall Murphy, Rogue Femtocell Owners: How Mallory Can Monitor My Devices, 5th IEEE International Traffic Monitoring and Analysis Workshop (TMA 2013), April 19, 2013. See also Richard Allen and Doug Kelly, Gaining root on Samsung FemtoCells, July 17, 2011, available at http://rsaxvc.net/blog/2011/7/17/Gaining%20root%20on%20Samsung%20FemtoCells.html. See also The Hackers Choice, The Vodafone Access Gateway, July 13, 2011, http://wiki.thc.org/vodafone. 251 See Golde et al (Weaponizing Femtocells) supra t x, p ge 7 (“T s ll ws n tt cke t impersonate any operator by utilizing a rogue femtocell as an inexpensive 3G IMSICatcher and wiretap device. Consequently, adversaries can intercept mobile communication by installing the dev ce n t e d nge f v ct .”) See also Erica Fink and Laurie Segall, Femtocell hack reveals mobile phones' calls, texts and photos, CNNMoney, July 15, 2013 http://money.cnn.com/2013/07/15/technology/security/femtocell-phone- ck/ ndex. t l (“In demonstration . . . researchers . . . covertly recorded one of our phone conversations and played it back for us. They were also able to record our browsing history, text messages, and even view p ct es we sent f ne s tp ne t n t e by ck ng t e netw k extende .”) 252 As noted in supra n. 233, it is possible, and in fact, likely, that sophisticated users will in time automate much of the difficult work required to modify the software running on femtocells, thus lowering the technical barriers that currently prevent less-sophisticated users from using femtocells to intercept calls. 253 This is not always the case. See fn 36 describing countries where encryption is not used for voice communications. Moreover, even when voice communications are encrypted, text messages may not

47

continues to use insecure encryption algorithms, many of which were created behind closed doors and without review by independent cryptography experts.254 Predictably, cryptography researchers have repeatedly discovered critical security flaws in the encryption algorithms designed and deployed by the cellular industry.255 Such flaws can be exploited to decipher the encrypted cellular signals captured with passive monitoring equipment. Moreover, even after researchers demonstrated that these encryption algorithms are vulnerable to interception, the cellular industry—including major US wireless carriers—continues to use them.256

be. See Magnus Glendrange, Kristian Hove, Espen Hvideberg, Decoding GSM, Thesis for Master of Science in Communication Technology, Norwegian University of Science and Technology, June 2010, page 161, http://www.diva-p t l. g/s s /get/d v 2:355716/FULLTEXT01.pdf , (“W en t e authors of this thesis asked the various operators, [the Norwegian cellular carrier] Telenor was the only company to admit that they were not encrypted. This fact is particularly surprising, given the vast amount of applications and services that today offer secure login through SMS. It seems to be optional for the operator to encrypt SMS, because we have reports of it being encrypted in Ge ny.”) 254 It has long been suspected that some of these encryption algorithms were intentionally weakened at the behest of government intelligence agencies. See Arild Færaas, Sources: We were pressured to weaken the mobile security in the 80's, Aftenposten, January 9, 2014, http://www.aftenposten.no/nyheter/uriks/Sources-We-were-pressured-to-weaken-the-mobile- security-in-the-80s-7413285.html (interviewing several experts involved with the creation of the original GSM A5/1 standard who claim the it was intentionally weakened as a result of pressure from the British government). See also John Perry Barlow, Decrypting the Puzzle Palace, Communications of the ACM, July 1992, available at http://groups.csail.mit.edu/mac/classes/6.805/articles/digital- telephony/Barlow_decrypting_puzzle_palace.html (describing the adoption by the US cellular nd st y f ntent n lly v lne ble enc ypt n lg t s kn wn t be “p t f lly e sy t b e k” s result of pressure by the NSA). See also Ross Anderson, A5 (Was: HACKING DIGITAL PHONES) , Post to uk.telecom mailing list, June 17, 1994, ttps://g ps.g gle.c /f /#! sg/ k.telec /TkdC yt eU4/M y719 d J (“[T] e e w s terrific row between the NATO signals agencies in the mid 1980's over whether GSM encryption should be strong or not. The Germans said it should be, as they shared a long border with the Evil Empire; but the other countries didn't feel this way. and the algorithm as now fielded is a French design.”) See also John Markoff, Researchers Crack Code in Cell Phones, New York Times, April 14, 1998, available at http://www.nytimes.com/1998/04/14/business/researchers-crack-code-in-cell- p nes. t l (“[A] d g t l key sed by G. .M. y ve been ntent n lly weakened during the design p cess t pe t G ve n ent genc es t e vesd p n cell l telep ne c nve s t ns”). 255 For example, the COMP128 cellular authentication algorithm was broken in two hours by Ian Goldberg and David Wagner, then graduate students at UC Berkeley. See Marc Briceno, RE: GSM security questions, Post to ukcrypto mailing list, October 21, 1999, archived copy available at http://cryptome.org/jya/gsm-weak.htm (revealing that he reverse-engineered the COMP128 and A5/2 lg t s “d ng evenings and on weekends over the course of a few months on a budget of well bel w $100.” I n G ldbe g nd D v d W gne t en c ypt n lyzed nd p ptly b ke t e lg t s n “2 s (COMP128) nd 2 d ys (A5/2…)”). See also David Wagner, Ian Goldberg and Marc Briceno, GSM Cloning, April 13, 1998, available at http://www.isaac.cs.berkeley.edu/isaac/gsm-faq.html. 256 As Steve Babbage, the Chairman of the ETSI SAGE group observed in 2007, the cost to the wireless carriers of replacing old cellular network equipment with newer, more secure technology is likely a j e s n f t e c e s’ dec de l ng del y n epl c ng lg t s kn wn t be s gn f c ntly flawed. See Steve Babbage, An update from ETSI SAGE, Security Algorithms Group of Experts, 2007, available at http://www.etsi.org/images/files/securityworkshop2007/Security2007S7_4_Steve_Babbage.pdf

48

One of the most widely used cellular telephone encryption algorithms, A5/1, was created by the wireless industry in 1988.257 A weakened version, known as A5/2, intended for use by non-Western countries, was developed five years later.258 The industry did not publish these algorithms, but in 1999 they were reverse engineered and finally subjected to review by independent security experts.259 Predictably, a team of graduate students broke the intentionally weakened,260 “exp t-g de” A5/2 algorithm in only a few hours after it was published.261 Several months later,262 a team of cryptographers discovered a critical flaw in the stronger A5/1

(“G M enc ypt n s pe f ed n t e b se st t n—and there are an awful lot of base stations in an operator network. Introducing substantially different algorithms typically requires a hardware upgrade, not just a software change. So upgrading a network to support a new GSM algorithm is very expens ve.”) 257 See ETSI Technical Report, Security Algorithms Group of Experts (SAGE); Report on the specification and evaluation of the GSM cipher algorithm A5/2, March 1996, page 8, available at ttp://www.ets . g/del ve /ets _et /200_299/278/01_60/et _278e01p.pdf (“T e lg t A5/1 was designed and approved in 1988/9 specifically for the then contemporary group of GSM MoU signatories. In the intervening years, international interest in GSM has grown, and the MoU now attracts signatories who are deploying or proposing to deploy GSM based cellular systems in many different parts of the world. This considerable increase in the number of countries in which GSM service will be provided is leading to potential conflict with various countries' restrictions on the export of products with cryptographic security features. To pre-empt this problem, the MoU decided to develop the second algorithm, A5/2, and to establish a policy governing its use and the use of A5/1.”) 258 See Id. (“ AGE st ted w k n A5/2 n N ve be 1992 nd del ve ed t e f n l spec f c t n nd test d t t t e M U ec ty R pp te n t e 31 M c 1993.”) 259 Orr Dunkelman, Nathan Keller, and Adi Shamir, A Practical-Time Attack on the A5/3Cryptosystem Used n T d Gene t n G M Telep ny, ttp://ep nt. c . g/2010/013.pdf (“T e p v cy nd security of GSM cellular telephony is protected by the A5 family of cryptosystems. The first two e be s f t s f ly, A5/1 … nd A5/2 … we e des gned n t e l te 1980’s n n p q e p cess nd we e kept sec et nt l t ey we e eve se eng nee ed n 1999 f ct l ndsets.”) 260 T e des gn g l f A5/2 w s t t “ t st p otect traffic on the GSM radio path so that such traffic is no more vulnerable to eavesdropping than on a Public Switched Telephone Network (PSTN) telep ne l ne.” T e lg t pp ently p ssed t s l w b , nd “ ll e be s f AGE st ted [prior to the lg t ’s ele se] t t t ey we e s t sf ed t t t e lg t w s s t ble t p tect g nst e vesd pp ng n t e G M d p t .” See ETSI Technical Report, infra. However, by 2007, after academic researchers had demonstrated significant security flaws in the algorithm, even the C n f t e AGE g p ckn wledged t t (“T e A5/2 enc ypt n lg t f G M s extremely weak — t p v des n p tect n t ll g nst e vesd pp ng.”) See Steve Babbage, An update from ETSI SAGE, Security Algorithms Group of Experts, 2007, available at http://www.etsi.org/images/files/securityworkshop2007/Security2007S7_4_Steve_Babbage.pdf 261 See post to uk crypto by Briceno, supra note 24; See also email from David Wagner to Christopher Soghoian, March 17, 2014, on f le w t t (“It took us about 5 hours to devise a break of A5/2.”) See also Ian Goldberg, David Wagner, and Lucky Green, The (Real-Time) Cryptanalysis of A5/2, Rump session of Crypto'99, 1999, slides available at http://www.cs.berkeley.edu/~daw/tmp/a52-sl des.ps . 262 See Alex Biryukov and Adi Shamir, Real Time Cryptanalysis of the Alleged A5/1 on a PC (preliminary draft), December 9, 1999. Final paper published as Alex Biryukov, Adi Shamir and David Wagner, Real Time Cryptanalysis of A5/1 on a PC, Fast Software Encryption, Lecture Notes in Computer Science Volume 1978, 2001, pp 1-18. See http://cryptome.org/a51-bsw.htm.

49

algorithm, opening the door to practical, real-time decryption of A5/1 protected communications.263 Even though the cryptography community considered A5/2 broken in 1999, the cellular industry did not phase out its use until 2007,264 and then only because new research demonstrated that the A5/2 capability in phones could be used to attack the security of Western A5/1 networks too.265 Today, the A5/1 algorithm, created in 1988 and thoroughly broken a decade ago, remains the most widely deployed cellular encryption algorithm in the world.266 Indeed, wireless carriers AT&T & T- Mobile still use the A5/1 algorithm f t e lde “2G” netw ks n the United States.267 Information about the strength of the encryption algorithms chosen by carriers, or whether encryption is used at all, is not readily made available to consumers, who reasonably might be alarmed to learn that the wireless carriers are not using the most secure encryption available (or in some cases, any at all) to protect their

263 During the decade that followed the A5/1 research by Biryukov and Shamir, several other research teams improved on this work, to make it more efficient to break. See Eli Biham and Orr Dunkelman, Cryptanalysis of the A5/1 GSM Stream Cipher, Progress in Cryptology, proceedings of Indocrypt '00, Lecture Notes in Computer Science 1977, Springer-Verlag, pp 43-51, 2000. See also Alexander Maximov, Thomas Johansson, and Steve Babbage. 2004. An improved correlation attack on a5/1. In Proceedings of the 11th international conference on Selected Areas in Cryptography (SAC'04), Helena Handschuh and M. Anwar Hasan (Eds.). Springer-Verlag, Berlin, Heidelberg, 1-18. See also Karsten Nohl, Attacking phone privacy, BlackHat 2010 Lecture Notes, July 28, 2010, https://srlabs.de/blog/wp-content/uploads/2010/07/Attacking.Phone_.Privacy_Karsten.Nohl_1.pdf 264 See generally Harald Welte, A brief history on the withdrawal of the A5/2 ciphering algorithm in G M, H ld Welte’s bl g, N ve be 12, 2010, v l ble t http://laforge.gnumonks.org/weblog/2010/11/12/. See also Osmocom Security, Withdrawal of A5/2 algorithim (sic) support, available at http://security.osmocom.org/trac/wiki/A52_Withdrawal. 265 The primary motivation for the cellular industry to withdraw A5/2 was not concern for the p v cy f se s n c nt es w e e A5/2 w s sed, b t t e , t e ex stence f “ llb ck” tt ck through which support by handsets for A5/2 could be used to force a phone connected to an A5/1 network to instead connect to a malicious base station. See Elad Barkan, Eli Biham, and Nathan Keller: Instant Ciphertext-Only Cryptanalysis of GSM Encrypted Communication, Crypto 2003, LNCS 2729, pp. 600-616, v l ble t ttp://www. . j . c. l/~nkelle /b _gs .pdf. (“T e c nt n ed v l b l ty f A5/2 s pp t t e tened A5/1 netw ks, nd s t w s w t d wn by t e nd st y.”) 266 See Craig Timberg and Ashkan Soltani, By cracking cellphone code, NSA has capacity for decoding private conversations, Washington Post, December 13, 2013, available at http://www.washingtonpost.com/business/technology/2013/12/13/e119b598-612f-11e3-bf45- 61f69f54fc5f_st y. t l (“M e t n 80 pe cent f cellp nes worldwide use weak or no encryption f t le st s e f t e c lls”)(q t ng cell l sec ty expe t K sten N l). 267 See GSM Map Project, GSM security country report: USA, Security Research Labs, Berlin, August 2013, page 4, available at http://gsmmap.org/assets/pdfs/gsmmap.org-country_report- United_States_of_America-2013-08.pdf (describing a survey of the security of AT&T and T-M b le’s US networks which revealed that the two forms of encryption used are A5/0 and A5/1. A5/0 is the no-encryption “n ll” option, and the A5/1 algorithm has been thoroughly broken by researchers.); See also e l f K sten N l t C st p e g n, Ap l 7, 2014, n f le w t t (“A5/1 s indeed used by AT[&]T and T-Mobile, but only for 2G voice and SMS. 3G already uses a much improved cipher that currently nobody knows how to crack...A5/0 is used in the US only for less p t nt t ns ct n[s] s c s eg l [netw k] pd tes, b t n t f c lls M .”).

50

communications. Indeed, the GSM standard requires that phones be capable of displaying a warning when no encryption is in use.268 However, the standard also permits wireless carriers to disable the encryption indicator, something that most do.269 Likely due to the fact that it was generally disabled and thus not displayed to consumers, many phone manufacturers, including some of the largest phone manufacturers such as Apple, Samsung, and Huawei, do not support the encryption warning feature in their phones.270 As such, there is generally no easy way for consumers to determine when their calls are unencrypted, or only protected with weak encryption algorithms. Although the academic research community has long documented the flaws in the encryption algorithms used by wireless carriers, these vulnerabilities could only be exploited by those with the resources to buy or build interception and decryption equipment. But just as software-defined radio technology has lowered the cost of active interception, so too has it provided researchers and hobbyists with the means to receive cellular signals that can then be deciphered using open source software that implements decade-old academic cryptographic research.271 Passive interception technology that once cost tens of thousands of dollars can now be built at home for as little as $15.272 Similarly, whereas cellular interception was once a black art practiced by those in the intelligence community, today, professors assign

268 See Iosif Androulidakis, Dionisios Pylarinos, and Gorazd Kandus, Ciphering Indicator approaches and user awareness, Maejo International Journal of Science and Technology, 2012, http://www.mijst.mju.ac.th/vol6/514-527.pdf at 3 (“A Ciphering Indicator was introduced [to the standards and it] was clearly stated that a notification should show the user the lack of data confidentiality. It was also stated that the Ciphering Indicator feature should be mandatory, enabled by default, [but] potentially switched off via the respective SIM setting controlled by the network operator. As such, even if a handset has implemented the feature, the operator is able to instruct it not to alert the user in the case of a loss of encryption”). 269 Id. 270 Id at 6 (“N ne d ffe ent n f ct e s n t e c ns de ed d t set ( p, sung, Qtek, HTC, Motorola, LG, Huawei, Chinabuye and Apple) did not employ a Ciphering Indicator, although this is eq ed by t e st nd ds.”) 271 See Magnus Glendrange, Kristian Hove, Espen Hvideberg, Decoding GSM, Thesis for Master of Science in Communication Technology, Norwegian University of Science and Technology, June 2010, page 161, http://www.diva-portal.org/smash/get/diva2:355716/FULLTEXT01.pdf at page 22 (“An lyz ng nd c pt ng G M t ff c w s p nt l ecently n nexpl ed e . T e n e s ns being the complex signaling mechanisms involved, the expensive hardware requirements and lack of interception software. However, things may be about to change with the emergence of open-source t ls…[t t en ble] ny ne w t nte est n G M sec ty t investigate the theoretical security p nc ples t g p ct c l pp c .”) See also A5/1 Decryption, Security Research Labs (Germany) https://opensource.srlabs.de/projects/a51-dec ypt (t e webs te f t e K ken t l, w c “ ll ws the 'cracking' of A5/1 keys sed t sec e G M 2G c lls nd M .”). 272 See J n B l nd, $15 p ne, 3 n tes ll t t’s needed t e vesd p n G M c ll, A s Tec n c , December 29, 2010, http://arstechnica.com/gadgets/2010/12/15-phone-3-minutes-all-thats- needed-to-eavesdrop-on-gsm-call/. See also Lucky Green, RE: New Yorker article on NSA surveillance, crypto regs, post to [email protected] mailing list, December 5, 1999, http://www.mail- c ve.c /c ypt g p [email protected]/ sg02532. t l (“I kn w w t b ld G M interception station using off-the-shelf hardware and [an Intel Pentium II processor] running Linux f t t l c st f well bel w U D 10k.”)

51

the task of decrypting cellular communications to their computer science students.273 The widespread availability of low-cost radio hardware, fast personal computers, and free open-source cellular interception and cryptanalysis software has made passive interception possible for any interested tech-savvy person, including criminals, enabling them to access conversations and other data previously only available to governments.274 These security threats are discussed next. VI. OUR VULNERABLE CELLULAR NETWORKS CAN BE AND ARE EXPLOTED BY OTHERS The US and other select global powers no longer enjoy a domestic monopoly over the use of cellular interception technology.275 Accordingly, a much larger number of hostile foreign intelligence services can and, almost certainly, are using the technology in this country for espionage. Similarly, if cellular interception technology is not already in use by criminals, the paparazzi and tech-savvy creepy neighbors, it is only a matter of time before they acquire and use it too. This Part will discuss these current and possible threats. A. FOREIGN GOVERNMENTS Cellular interception technology can be a critical tool in intelligence operations.276 In contrast to law enforcement surveillance, for example, where the assistance of a wireless carrier is often available, intelligence agencies operating without the knowledge or assistance of local governments cannot obtain information from wireless carriers.277 As such, cellular interception devices are often the only way for intelligence agencies to monitor the communications of targets. Indeed, as a result of the disclosures to the media by Edward Snowden, it is now clear (and not surprising) that the US National Security Agency (NSA) uses both active and passive cellular interception technology. T e N A’s pec l C llect n Service reportedly uses passive cellular interception devices installed at US

273 See Gerhard Schneider, Konrad Meier and Dennis Wehrle, Practical exercise on the GSM Encryption A5/1, February 23, 2011, http://www.data.ks.uni- freiburg.de/download/misc/practical_exercise_a51.pdf 274 It should be noted that the research team that has in recent years lead the way in demonstrating significant, practical flaws in the A5/1 algorithm has intentionally not published step-by-step instructions to decrypt calls. See Karsten Nohl, Use Motorola C123 to capture gsm, post to A51 mailing list, August 11, 2013, available at https://lists.srlabs.de/pipermail/a51/2013-

A g st/001268. t l (“We e n t p bl s ng tt ck t t ls. T e line we are walking—between warning about possible abuse and enabling it— s l e dy ve y f ne.”) H weve , t s l st ce t n that others will fill this void by documenting the process. 275 See supra Part V. 276 See supra Part II.B. See also Morrison Affidavit, supra note **. 277 See supra Part II.B.

52

embassies and consulates around the world to spy on the telephone calls of foreign leaders.278 More specifically, an internal NSA surveillance product catalog describes active cellular interception devices that are available for use by agents conducting intelligence operations.279 Just as US intelligence agencies use cellular interception technology to perform surveillance in foreign countries, it is reasonable and prudent to assume that foreign intelligence agencies who are known to operate in Washington D.C are doing the same.280 National security reporters Marc Ambinder and D.B. Grady have hinted at the existence of cellular surveillance activities by foreign governments, claiming that “[t] e FBI s q etly e ved f seve l W s ngt n, D.C.–area cell phone towers, transmitters that fed all data to . . . f e gn e b ss es.”281 When asked about the claim by the Washington Post, the FBI declined to comment.282 As P es dent Ob s n ted, “we know that the intelligence services of other c nt es … are constantly probing our government and private sector networks and accelerating programs to listen to our conversations.” It is for that reason, he dded, t t “Bl ckBe ys and iPhones are not allowed in the White House Situation Room.”283 Although the NSA takes steps to protect the communications of the President and other senior national security officials from foreign intelligence

278 See DRTBOX and the DRT surveillance systems, Top Level Telecommunications, December 8, 2013, available at http://electrospaces.blogspot.com/2013/11/drtbox-and-drt-surveillance- systems.html (Describing the DRT family of cellular surveillance products manufactured by Boeing nd n lyz ng t e l kely se by t e N A, b sed n efe ences t “DRTB x” n N A d c ents le ked by Edward Snowden). See also Spiegel/Duncan Campbell, infra, (currently fn 69). 279 See CANDYGRAM – GSM Telephone Tripwire, http://leaksource.files.wordpress.com/2013/12/nsa-ant-c ndyg .jpg (“M cs G M cell t we f a target network.... Typical use scenarios are asset validation, target tracking and identification as well as identifying hostile surveillance un ts w t G M ndsets.”) See also Jacob Appelbaum, Judith Horchert and Christian Stöcker, Shopping for Spy Gear: Catalog Advertises NSA Toolbox, December 29, 2013, http://www.spiegel.de/international/world/catalog-reveals-nsa-has-back-doors-for- numerous-devices-a-940994.html 280 See Matthew M. Aid, The Spies Next Door, Foreign Policy, September 21, 2012, http://www.foreignpolicy.com/articles/2012/09/21/the_spies_next_door (“On a per capita basis, there are more spies working in and around the Beltway than anywhere else in the world. Almost half of the 200,000 men and women who belong to the U.S. intelligence community work in Washington, as do several thousand foreign intelligence officers who operate openly from dozens of embassies and international organizations in the U.S. capital, trawling the landscape for secrets.”)(e p s s dded). 281 Marc Ambinder and D.B. Grady, Deep State: Inside the Government Secrecy Industry, April 1, 2013, Wiley and Sons, p 245. 282 Craig Timberg and Ashkan Soltani, By cracking cellphone code, NSA has capacity for decoding private conversations, Washington Post, December 13, 2013, available at http://www.washingtonpost.com/business/technology/2013/12/13/e119b598-612f-11e3-bf45- 61f69f54fc5f_story.html. 283 See Transcript of President Ob ’s J n. 17 speec n N A ef s, F d y, J n y 17, v l ble at http://www.washingtonpost.com/politics/full-text-of-president-obamas-jan-17-speech-on-nsa- reforms/2014/01/17/fa33590a-7f8c-11e3-9556-4a4bf7bcbd84_story.html

53

agencies, they are the exception, not the norm.284 There are many other people who participate, directly or indirectly, in this c nt y’s p l cy p cess—such as Members of Congress, civil servants, as well as journalists, lawyers and lobbyists—whose communications are both intelligence-rich and vulnerable, thus likely targeted by foreign intelligence agencies. Moreover, cellular interception equipment is equally useful for non-political espionage conducted by foreign governments. Specifically, this technology can be used in business centers like New York or Silicon Valley for industrial espionage or to gain insider knowledge by monitoring the communications of business executives, financiers and entrepreneurs.285 B. NON-GOVERNMENT USE OF CELLULAR INTERCEPTION TECHNOLOGY If cellular interception technology were still prohibitively expensive and exclusively available to governments engaged in foreign and domestic surveillance, the communications of the average law-abiding American would rarely be targeted.286 After all, intercepting telephone calls on US soil will presumably focus their efforts on the tiny percentage of Americans whose communications have some significant strategic or intelligence value. With respect to the average American’s exposure to private communications interception, however, history appears to be repeating itself. Just as the radio scanners of the 1990’s enabled nearly anyone to intercept a ne g b ’s analog phone communications, modern cellular interception devices are now available for purchase over the Internet from surveillance technology resellers around the world for a few thousand dollars each.287 Moreover, they are far easier to use than the

284 See Michael S. Schmidt and E c c tt, Ob ’s P t ble Z ne f ec ecy ( e Asse bly Required), New York Times, November 9, 2013, available at http://www.nytimes.com/2013/11/10/us/politics/obamas-portable-zone-of-secrecy-some- assembly- eq ed. t l (“C nte e s es e t ken n American soil as well. When cabinet secretaries and top national security officials take up their new jobs, the government retrofits their homes with special secure rooms for top-sec et c nve s t ns nd c p te se.”) 285 See James Clark, French spies listen in to British calls, The Sunday Times (UK), January 24, 2000 (“F enc ntell gence s nte cept ng B t s b s ness en’s c lls ... E vesd ppe s c n ‘pl ck’ G M digital mobile phone signals from the air by targeting individual numbers or sweeping sets of numbers. Targets have included executives at British Aerospace, British Petroleum and British A w ys.”) 286 The strategic targeting practices of foreign governments do not, however, completely insulate innocent, law-abiding Americans from having their communications monitored incidentally by US and foreign government agencies. As described in Part II, this surveillance technology is by its very nature overbroad in its operation, capturing data about many other phones in the vicinity of the area where it is used. 287 See supra **.

54

homemade models built by researchers,288 making them an attractive tool for criminals, private investigators and paparazzi.289 In the Czech Republic, for example, law enforcement and intelligence officials have voiced concerns about the threat posed by cellular interception technology. In 2012, the head of the Czech Criminal Police unit for wiretapping told the national public radio service that his team had detected non-police active interception devices in use around the country.290 He speculated that the most likely private users of the devices were security firms and rival businesses engaged in industrial espionage.291 Similarly, the ex-head of the Czech Military Intelligence Agency expressed fears about potential widespread availability and sale of such technology, stating, “if their use will not be in any way regulated, and access to these devices will not be in any way controlled, then a regular citizen can do absolutely nothing [to safeguard their c n c t ns].”292 While commercial cellular interception technology is, for now, probably too expensive for the average stalker or garden variety criminal, the cost of these devices will, like all technology, decrease over time.293 At just a few thousand dollars each, however, commercial cellular interception devices are already affordable for sophisticated domestic or multi-national criminal organizations (e.g. organized crime), companies engaging in industrial espionage, private investigators and paparazzi. And for the technically skilled criminal, no matter the scale of his operations, cellular interception technology is already affordable. Although cellular interception devices are not yet in widespread private use in the US,294 they are certainly no longer a secret. To suggest otherwise is to embrace and propagate a fiction: these technologies have been globalized, democratized, and the vulnerabilities they exploit now threaten the privacy of hundreds of millions of Americans who use cellular telephones to communicate. Indeed, the use of cellular interception devices in India and the Czech Republic paints a worrisome picture of 288 See supra **. 289 We are not suggesting that it would be legal for private parties to intercept the conversations of other. The chance of being discovered intercepting calls, however, is extremely low, even more so when passive surveillance technology is used. 290 See Masha Volynsky, Spy games turn real as eavesdropping technology spreads, Radio Praha, August 16, 2012, http://www.radio.cz/en/section/curraffrs/spy-games-turn-real-as-eavesdropping- technology-spreads. 291 Id. 292 Id. 293 See generally Douglas McCormick, Wright's Law Edges Out Moore's Law in Predicting Technology Development, IEEE Spectrum, July 25, 2012, http://spectrum.ieee.org/tech-talk/at-work/test-and- measurement/wrights-law-edges-out-moores-law-in-predicting-technology-development (describing a research paper that compares various models, including Moore’s Law, all of which attempt to predict the decrease in the price of technologies over time) 294 This does not mean they have not been used at all. According to national security journalist Marc A b nde , “T e ec et e v ce s c g t pe ple s ng t ng ys t c llect pe s n l d t f se n f n nc l f d c ses.” See Marc Ambinder, email to Christopher Soghoian, May 13, 2013, on file with author.

55

the potential threat. Even so, US government agencies continue to treat cellular interception equipment as a closely guarded secret, even protecting the name of the equipment they use.295 As discussed next, the consequence of embracing this erroneous, tendentious narrative, which grants surveillance priority over the security of communication networks, is that the American public remains vulnerable to cellular interception by a variety of non-US government actors. VII. A HIGH PRICE TO PAY FOR THE FICTION OF SECRECY The analog phone vulnerabilities of the 1990s were no secret. The technology required to intercept calls was widely available and several high-profile abuses led to front-page scandals involving the communications of the rich and powerful. In response, Congress held hearings, the cellular industry weighed in, and ultimately, the Federal Communications Commission (FCC) promulgated regulations intended to limit the ease with which interception technology could be obtained.296 Although the approach adopted by policy makers and regulators—seeking to prohibit the sale of interception equipment, rather than mandating technical solutions capable of securing communications from interception— was ultimately ineffective, Congress and the FCC at least acknowledged the problem and did something to try and address it. The Congress of the 1990s held public hearings focused on cellular interception vulnerabilities;297 the Congress of the 2010s has not—and if congressional committees have even been briefed on the issue, those briefings have occurred behind closed doors. The FCC of the 1990s adopted regulations intended to protect cellular communications from interception;298 the FCC of the 2010s perpetuates the fiction that cellular interception is a secret capability available only to government agencies by shielding most information about cellular interception equipment from public disclosure, hence from public awareness and consideration.299 Whereas the cellular vulnerabilities of the 1990s were treated as a threat to the nation’s cell l network, today, the Department of Homeland Security (DHS), whose stated mission includes protecting critical infrastructure and information networks,300 also appears t ve e b ced t e “sens t ve s ce nd et d” n t ve by w t ld ng relevant documents about cellular interception technology from the public.

295 See supra Part IV. 296 See supra Part I. 297 See supra Part I. 298 See supra Part I. 299 See Julius P. Knapp, Chief, Office of Engineering and Technology, Federal Communications Commission, Letter to Christopher Soghoian, February 29, 2012, http://files.cloudprivacy.net/FOIA/FCC/fcc-stingray-reply.pdf t 3 (“We are withholding certain intra-agency and interagency emails and documents because they are classified or because taken together with other information they could endanger national and homeland security."). 300 See US Department of Homeland Security, Mission, ttp://www.d s.g v/ ss n (“O d t es e wide-ranging, but our goal is clear: a safer, more secure America, which is resilient against terrorism nd t e p tent l t e ts… [DH ] w ks w t nd st y nd st te, l c l, t b l nd territorial g ve n ents t sec e c t c l nf st ct e nd nf t n syste s.”).

56

In 2013, then-FCC Act ng C w n M gn n Clyb n st ted t t “protecting consumer privacy is a key component of [t e FCC’s] mission to serve the public interest.301 Her predecessor, former FCC Chairman Julius Genachowski had similarly acknowledged that the Commission d been d ected by C ng ess t “protect the privacy of consumers who rely on our Nation's communications infrastructure.”302 To date, however, the FCC appears to have done nothing other than accommodate and perpetuate the fictional secrecy narrative authored by law enforcement agencies and cellular surveillance equipment manufacturers. Indeed, the agency continues to grant equipment authorizations (and the requested protections from public disclosure) for each new cellular surveillance product the Harris Corporation seeks to market to law enforcement agencies.303 Together with the FCC, DHS shares the responsibility for protecting the security of A e c ’s civilian telephone networks. DHS is also a law enforcement agency, with component agencies that have spent millions of dollars on StingRays and other cellular interception equipment.304 Moreover, DHS funds the acquisition of cellular interception equipment by state and local law enforcement agencies.305 Likewise, as the primary regulator of the wireless and wireline carriers, the FCC has repeatedly used its regulatory powers to force telecommunications companies to facilitate 301 See Statement of Acting Chairwoman Mignon Clyburn, Re: Implementation of the Telec n c t ns Act f 1996: Telec n c t ns C e s’ Use f Customer Proprietary Network Information and Other Customer Information, CC Docket No. 96-115, http://transition.fcc.gov/Daily_Releases/Daily_Business/2013/db0627/FCC-13-89A2.pdf. 302 Consumer Online Privacy: Hearing Before the S. Comm. on Commerce, Science and Transportation, 111th Cong. (2010), Statement of FCC Chairman Julius Genachowski, available at http://www.gpo.gov/fdsys/pkg/CHRG-111shrg67686/html/CHRG-111s g67686. t (“T e g t to privacy is central to our Nation's values and way of life, and the Federal Communications Commission has long worked to implement Congress's directive to protect the privacy of consumers w ely n N t n's c n c t ns nf st ct e.”). Id. 303 See supra n. 185. 304 See supra n. 76. 305 See Federal Support For and Involvement In State and Local Fusion Centers, Report of United States Senate Permanent Subcommittee on Investigations, Committee on Homeland Security and Governmental Affairs, October 3, 2012 at 87, available at http://www.hsgac.senate.gov/download/?id=49139e81-1dd7-4788-a3bb-d6e7d97dde04 (describ ng t e se f FEMA g nt t p c se “s p st c ted cell p ne t ck ng dev ces” by t e Washington D.C. Homeland Security and Emergency Management Agency.); See also Michael Bott and Thom Jensen, Cellphone Spying Technology Being Used Throughout Northern California, News 10, March 6, 2014, http://www.news10.net/story/news/investigations/watchdog/2014/03/06/cellphone-spying- technology-used-throughout-northern-california/6144949/ (“StingRays are being paid for mostly by Homeland Security grant money distributed by the California Emergency Management Agency, under programs such as the Urban Areas Security Initiative (UASI) or the State Homeland Security Program (SHSP).”); See also City of Tacoma, WA, City Council Minutes, March 19, 2013, at 1, available at http://cms.cityoftacoma.org/cityclerk/Files/CityCouncil/Minutes/2013/CCMin20130319.pdf (“A t z ng t e exec t n f g nt g ee ent w t t e U.S. Department of Homeland Security Port Security Grant Program n t e nt f $188,814.31 … [t p c se f om the] Harris C p t n … tec n c l s pp t eq p ent t ss st n t e p event n, detect n, esp nse, nd ec ve y f p v sed expl s ve dev ces.”).

57

surveillance by law enforcement and intelligence agencies.306 These two agencies t s we t e p ve b l “tw ts,”307 enabling or engaging in surveillance on one hand, while they are clearly tasked with protecting the security of communications networks on the other. These dual roles and objectives can, in theory and practice, come into conflict when choices must be made to prioritize either surveillance or security. With respect to the dual surveillance and security responsibilities under the jurisdiction of these federal agencies, an uncritical adoption of the law enforcement narrative can have the effect of suppressing an equally compelling counter- narrative: Americans' cellular communications are vulnerable to interception by foreign governments and criminals. We d n’t kn w f t w t extent officials at the FCC or DHS have made an actual policy choice and taken action to prioritize cellular interception over the security of cellular networks. In other words, by withholding most, if not all information about cellular interception technology, are t ey nc t c lly nd eflex vely pe pet t ng t e “sens t ve s ce nd et d

306 The FCC has repeatedly used the license granting process to extract surveillance enabling concessions from service providers that are not required by law. See Craig Timberg and Ellen N k s , Ag ee ents w t p v te c p n es p tect U. . ccess t c bles’ d t f s ve ll nce, Washington Post, July 6, 2013, available at http://www.washingtonpost.com/aa5d017a-df77-11e2- b2d4-e 6d8f477 01_st y. t l (“Neg t t ng leve ge s c e f see ngly nd ne government power: the authority of the Federal Communications Commission to approve cable licenses. In deals involving a foreign company, say people familiar with the process, the FCC has held up approval for many months while the squadron of lawyers dubbed Team Telecom developed sec ty g ee ents t t went bey nd w t’s eq ed by t e l ws g ve n ng elect n c e vesd pp ng.”) See also Statement of Stewart Baker, Partner, Steptoe & Johnson. Hearing on “F t A end ent And T e Inte net,” H se J d c y C ttee, bc ttee n t e Constitution, page 135, April 6 2000. ttp://c d cs. se.g v/c ttees/j d c y/ j 66503.000/ j 66503_0f. t (“The FBI and the Justice Department have intervened repeatedly at the [Federal Communications Commission] to try to deny licenses to companies that have not been fully cooperative or that have developed new technologies that the FBI thinks should be more accessible [to surveillance]. This is all in an effort to get the FCC, usually successfully, to deny licenses to operate in the United States to companies that have not cooperated with the Bureau. They did this to Iridium when Iridium wanted to locate a ground station in Canada. They did it in the BT-MCI merger. And it has become a regular feature of mergers where foreign companies propose to provide telecommunications services in the United t tes.”). T e FCC s ls eq ed t e etent n f telep ne c ll records by telephone companies, specifically as a result of a petition by the Justice Department. See More Misleading Information from ODNI on NSA Telephone Metadata Collection , July 24, 2013, available at http://www.docexblog.com/2013/07/more-misleading-information-from- dn . t l (“T e [telephone] retention period had previously been six months, but the DOJ petitioned the FCC to extend t p ec sely bec se s c telep ne ec ds ‘ e ften essent l t t e s ccessf l nvest g t n and prosecution of today's sophisticated criminal conspiracies relating, for example, to terrorism . . . nd esp n ge.’ T e FCC t e ef e extended t e leg l etent n pe d f s l ng s t e DOJ s d w s necess y.”). 307 These are not the only agencies that have conflicting missions. The National Security Agency has been criticized for prioritizing its offensive mission over defense. See Bruce Schneier, Breaking Up the NSA, CNN Opinion, February 20, 2014, http://www.cnn.com/2014/02/20/opinion/schneier- nsa-too-big/index.html (“[The NSA] is an agency that prioritizes intelligence gathering over security, and that's increasingly putting us all at risk”).

58

n t ve” , much worse, are they participating in a strategic choice to embrace this fiction as part of their regulatory roles? One detrimental side effect of viewing cellular interception equipment completely from a law enforcement agency perspective—and by doing so indirectly prioritizing law enforcement and intelligence surveillance equities—is that policy makers and regulators are unlikely to address the underlying vulnerabilities in American cellular networks. Indeed, to date, there has been no public effort to address the cellular network security vulnerabilities or to warn the public about them, while DHS and the FCC have actively enabled the ongoing exploitation of these vulnerabilities by US government agencies. If the existence of and knowledge about these vulnerabilities were truly a secret and the technology that exploits them was only available to US government agencies, perhaps this blinkered view might be a reasonable policy trade off. That is only so, however, if law enforcement surveillance capabilities could be protected without placing the American public at risk. But they cannot, so this scenario does not describe reality. The secrecy is a fairytale, while the long term impact of the technology may lead to a privacy and security nightmare. Indeed, security researchers have publicly documented the flaws exploited by cellular interception technology, while it is used by foreign governments and readily available to technologically sophisticated criminals, private investigators, and the paparazzi. Meanwhile, law-abiding citizens and businesses remain in a government-willed darkness on the matter, exposed to a myriad of interception risks. If policy makers understand and treat cellular network vulnerabilities as part of the existing debate about cyber security, however, perhaps rational public discourse and work towards an informed balance of risks and rights could begin. That debate and the rightful place of cellular network security in that discourse is addressed next. VIII. FOCUSING ON CYBER SECURITY The United States faces a serious cyber security threat.308 Foreign governments like China have repeatedly hacked into the computer systems of government agencies and major U.S. companies, including technology firms and defense contractors, to steal intellectual property and classified information.309 James Clapper, the Director

308 See Mitchell S. Kominsky, The Current Landscape of Cybersecurity Policy: Legislative Issues in the 113th Congress, H v d N t n l ec ty J n l (Feb. 6, 2013) (“Cybersecurity represents one of the most serious national security threats and economic challenges confronting our country. Cybercrime costs the United States approximately $100 billion annually . . . . Based on information shared by technology and cryptology experts, combined with the response by both the private market and the federal government, the cyber threat is quickly becoming the top priority for our national defense apparatus and private enterprise.”). 309 See Ellen Nakashima, Confidential report lists U.S. weapons system designs compromised by Chinese cyberspies, Washington Post, May 27, 2013,

59

of National Intelligence and James Comey, the Director of the FBI have both told Congress that cyber-attacks are the most serious national security threat faced by the United States.310 In response to these cyber security threats and the responsive warnings of senior government and industry officials, Congress has held numerous hearings and proposed legislation.311 T e W te H se s pp nted “cybe sec ty cz ,”312 genc es e g ven cybe sec ty “g des” (to date many failing ones),313 and the government spends billions of dollar every year on cyber security with no reduction of risks in sight.314 Although most of the cyber security concerns expressed by government leaders pertain to the security of government networks and so called “critical infrastructure,”315 such as the electronic power grid and the computer systems controlling power pl nts, A e c ’s telep ne netw ks ve n t c pletely

http://www.washingtonpost.com/world/national-security/confidential-report-lists-us-weapons- system-designs-compromised-by-chinese-cyberspies/2013/05/27/a42c3e1c-c2dd-11e2-8c3b- 0b5e9247e8ca_story.html. See also Jim Finkle, Hacker group in China linked to big cyber attacks: Symantec, Reuters, September 17, 2013, http://www.reuters.com/article/2013/09/17/us- cyberattacks-china-idUSBRE98G0M720130917. See also Michael Riley and Ben Elgin, C n ’s Cybe sp es O tw t M del f B nd’s Q, Bl be g, M y 2, 2013, http://www.bloomberg.com/news/2013-05-01/china-cyberspies-outwit-u-s-stealing-military- secrets.html 310 See Jim Garamone, Clapper Places Cyber at Top of Transnational Threat List, Armed Forces Press Service, March 12, 2013, http://www.defense.gov/news/newsarticle.aspx?id=119500. See also Greg Miller, FBI director warns of cyberattacks; other security chiefs say terrorism threat has altered, Washington Post, November 14, 2013, http://www.washingtonpost.com/world/national- security/fbi-director-warns-of-cyberattacks-other-security-chiefs-say-terrorism-threat-has- altered/2013/11/14/24f1b27a-4d53-11e3-9890- 1e0997fb0c0_st y. t l (“FBI D ect J es B. Comey testified Thursday that the risk of cyberattacks is likely to exceed the danger posed by al- Qaeda and other terrorist networks as the top national security threat to the United States and will bec e t e d n nt f c s f l w enf ce ent nd ntell gence se v ces.”) 311 See, for example, The Cyber Intelligence Sharing and Protection Act (CISPA H.R. 3523 (112th Congress), H.R. 624 (113th Congress)). 312 See Michael Hardy, New White House cyber czar brings intel chops, Federal Computer Week, June 4, 2012, http://fcw.com/articles/2012/06/15/buzz-howard-schmidt-michael-daniel-cyber- czar.aspx. 313 See Brian Krebs, Federal Government Sees Modest Computer Security Gains, Washington Post, April 12, 2007, http://www.washingtonpost.com/wp- dyn/content/article/2007/04/12/AR2007041201010.html 314 See Amber Corrin, Budget shows how cyber programs are spreading, Federal Computer Week, April 12, 2013, http://fcw.com/Articles/2013/04/12/budget-cybe sec ty. spx (“T e DH f g e includes nearly $500 million for cybersecurity research and development and almost $1 billion exp essly f t e p tect n f fede l c p te s nd netw ks g nst l c s cybe ct v ty.”) See also Andy Sullivan, Obama budget makes cybersecurity a growing U.S. priority, Reuters, April 10, 2013 http://www.reuters.com/article/2013/04/11/us-usa-fiscal-cybersecurity- dU BRE93913 20130411 (“Ob 's b dget, ele sed n Wednesd y, p p ses t b st Defense Dep t ent spend ng n cybe eff ts t $4.7 b ll n, $800 ll n e t n c ent levels”). 315 See, f ex ple, Exec t ve O de (EO) 13,636, “I p v ng C t c l Inf st ct e Cybe sec ty,” and Presidential Policy Directive (PPD)-21, “C t c l Infrastructure Security and Resilience.

60

escaped the attention of policy makers. Sparked by fears that Chinese communications equipment companies, such as Huawei and ZTE, may have hidden surveillance backdoors in their products at the request of the Chinese government,316 the US national security establishment responded.317 According to media reports, both AT&T and Sprint, which had planned to purchase Huawei equipment for their next generation 4G networks, were threatened by senior officials in the national security community with a consequent loss of government business and the disruption of merger plans.318 Ultimately, both companies did not purchase Huawei equipment, instead opting for network hardware from Western manufacturers.319 The House Intelligence Committee also investigated the matter, holding a hearing where executives from both Huawei and ZTE testified. In his opening remarks at t t e ng, C ttee C n M ke R ge s st ted t t “A e c ns ve t t st 316 See T e N t n l ec ty I pl c t ns f Invest ents nd P d cts f t e Pe ple’s Rep bl c f China in the Telecommunications Sector, U.S.-China Economic and Security, January 2011, http://origin.www.uscc.gov/sites/default/files/Research/FINALREPORT_TheNationalSecurityImplic ationsofInvestmentsandProductsfromThePRCintheTelecommunicationsSector.pdf. See also Jeremy Wagstaff and Lee Chyen Yee, ZTE confirms security hole in U.S. phone, Reuters, May 18, 2012, http://www.reuters.com/article/2012/05/18/us-zte-phone-idUSBRE84H08J20120518. 317 See David E. Sanger and Nicole Perlroth, N.S.A. Breached Chinese Servers Seen as Security Threat, New York Times, March 22, 2014, http://www.nytimes.com/2014/03/23/world/asia/nsa- breached-chinese-servers-seen-as-spy-peril.html (“W s ngt n’s c nce ns b t H we d te b ck nearly a decade, since the RAND Corporation, the research organization, evaluated the potential threat of China for the American l t y. RAND c ncl ded t t ‘private Chinese companies such as H we ’ we e p t f new ‘digital t ngle’ of companies, institutes and government agencies that worked together secretly”) Sanger, supra note 311, (“[A e c n ff c ls] have blocked [Huawei] at every turn: pressing Sprint t k ll $3 b ll n de l t b y H we ’s f t gene t n, 4G, netw k technology; scuttling a planned purchase of 3Com for fear that Huawei would alter computer code sold to the United States military; and pushing allies, like Australia, to back off from major projects.”); See also John Pomfret, History of telecom company illustrates lack of strategic trust between U.S., China, The Washington Post, October 8, 2010, available at http://www.washingtonpost.com/wp- dyn/content/article/2010/10/07/AR2010100707210. t l (“T e ess ge f t e N A … w s simple: If AT&T wanted to continue its lucrative business with the U.S. government, it had better select a supplier other than Huawei.”); See also Antonio Regalado, Before Snowden, There Was Huawei, MIT Technology Rev ew, (“Anyt e [H we s ne ] t cl s ng s le, t e c st e s get v s t f t e FBI U. . Dep t ent f C e ce. T e ess ge f t e feds sn’t s btle: b y s et ng else.”). 318 Id. 319 See John Pomfret, Id. (“In February, AT&T announced that it would buy the equipment it needed from Swedish-owned Ericsson and Paris-based Alcatel-Lucent.”) ee ls Edw d Wy tt, Sprint Nears a U.S. Deal to Restrict China Gear , New York Times, March 28, 2013, http://www.nytimes.com/2013/03/29/business/sprint-and-softbank-near-agreement-to-restrict- use-of-chinese-suppliers.html (“Seeking to address national security concerns, Sprint Nextel and SoftBank, its Japanese suitor, are expected to enter an agreement with American law enforcement officials that will rest ct t e c b ned c p ny’s b l ty t p ck s ppl e s f ts telec n c t ns equipment and systems. The agreement would allow national security officials to monitor changes to t e c p ny’s syste f te s, se ve s nd sw tc es, ng t e eq p ent and processes… SoftBank and Sprint have already assured members of Congress that they will not integrate eq p ent de by H we nt p nt’s Un ted t tes syste s nd w ll epl ce H we eq p ent n Cle w e’s netw k.”).

61

our telecommunications netw ks” nd t t “[w] en v lne b l t es n t e eq p ent … c n be expl ted by n t e c nt y, t bec es p ty nd n t n l sec ty c nce n.”320 After the hearing, the Committee released a bi- partisan report accusing the companies of collaborating with the Chinese military.321 Significantly, from a policy perspective, when faced with the possibility that US telecommunications networks might be vulnerable to exploitation by the Chinese government through security flaws or backdoors, Congress and members of the national security community swiftly examined the problem and took decisive action. In contrast to the resources directed at these Chinese supply chain threats, nothing approaching this kind of effort and focus has been channeled towards other existing security vulnerabilities in our cellular networks that can and are being exploited by the intelligence services of many countries. While there are a number of likely reasons why the perceived threat posed by Huawei and ZTE became such a high-profile issue for policy makers, it is worth n t ng t t t e “f x” t t s p ble w s t e s ple—pressuring major US carriers such as AT&T and Sprint to purchase equipment from Western (thus “trusted”) suppliers of cellular network equipment rather than Huawei and ZTE. The companies that made the mistrusted products are Chinese and thus subject to ready and politically safe (indeed, in some cases politically rewarding) demonization by the intelligence community and their allies in Congress. Moreover, the national security threat posed by Chinese government exploitation of backdoors in Chinese telephony equipment, unlike many other threats, offered the inherent political benefit of being legally amenable to public discussion without putting any US government intelligence sources and methods at risk. In contrast to the Huawei and ZTE threat, the risks posed by the cellular network vulnerabilities described in this Article present a far more politically delicate problem. The technical fix for them may be expensive and time consuming,322 and

320 RepMikeRogers, Huawei and ZTE Testify Before the House Intel Committee Part 1, YouTube at 4:17 (Oct. 3, 2012), http://www.youtube.com/watch?v=ApQjSCUpt4s 321 See H. Permanent Select Comm. on Intelligence, 112th Cong., Chairman and Ranking Member Investigative Report on the U.S. National Security Issues Posed by Chinese Telecommunications Companies Huawei and ZTE, 2, 11 (2012) (Chairman Mike Rogers and Ranking Member Dutch Ruppersberger), https://intelligence.house.gov/sites/intelligence.house.gov/files/documents/Huawei- ZTE%20Investigative%20Report%20(FINAL).pdf. 322 See Babbage supra note ** (currently fn 256). The cost may not be significant if the carriers are already upgrading their networks. See email from Karsten Nohl to Christopher Soghoian, April 21, 2014, on file with author (“The biggest cost item is the replacement of old 2G base stations. This

replacement is done anyway in most networks when introducing 4G/LTE—2G comes as part of the new 4G base stations which replace existing 2G cells and these new cells all support A5/3. The

incremental cost of turning on A5/3 becomes small—on the order of millions of dollars. The cost is especially small when contrasted with the decision against Huawei and ZTE equipment: Sourcing an entire 4G network from non-Chinese suppliers easily adds a few billions to the bill.”)

62

the companies that have long known about these vulnerabilities in their networks yet have neither fixed the vulnerabilities nor warned consumers about the risks are large, politically active US corporations. Moreover, the devices that exploit these vulnerabilities, which are also manufactured by large, politically active defense contractors, are considered sensitive sources and methods that US law enforcement and intelligence agencies would undoubtedly prefer not to be the subject of open discussion at public hearings. It is therefore not surprising that policy makers have failed to tackle this issue, whether in the context of the existing cyber security debate or otherwise. Although, to date, policy makers and regulators have not demonstrated much public interest in the easily exploitable security vulnerabilities in our cellular networks, it is likely that, at some point, circumstances will force them to do so. Whether in responding to future media disclosures related to government surveillance, or to the threat posed by foreign government or private use of interception technology, Congress and the FCC will eventually have to look for solutions to the problem. We examine some possible solutions next. IX. PROTECTING OUR COMMUNICATIONS The cellular communications of billions of people around the world are vulnerable to interception by their own governments, other governments, and tech-savvy criminals. Although these risks and the consequent need for more secure communication technologies are still not widely known in the United States, that will likely change over time. Whether a result of interest and pressure by policy makers and communications regulators, or the media attention that will arise if a few high-profile examples of private interception occur, Americans will eventually learn enough about the endemic insecurity of domestic cellular communications networks that the issue will be forced into the public debate, prompting political actors and the cellular industry to respond. By upgrading the security of their networks, the wireless carriers could protect their customers from unmediated cellular interception technology. Such upgrades, however, are neither cheap nor easy to perform, given the significant size and reach f U cell l netw ks. Alte n t vely, c ns e s’ c n c t ns could be protected by transitioning to more-secure, Internet-based voice and text communications services that work on top of cellular data and WiFi networks. While a thorough examination of the solutions and the regulatory process necessary to execute them is beyond the scope of this article, this Part will examine the two likely technical avenues through which solutions could come. A. SECURING CELLULAR NETWORKS If the wireless carriers and the phones used by their customers exclusively employed modern cellular encryption algorithms, most of the cellular interception vulnerabilities described in this Article would be cured. But the wireless industry

63

has not switched to modern cryptography. Wireless carriers continue to use weak algorithms that were designed in the 1980s and broken in the 1990s.323 Indeed, the outmoded A5/1 algorithm remains the most widely deployed cellular encryption algorithm in the world. An improved encryption algorithm, A5/3, was developed and standardized by the cellular industry in 2002. A5/3-capable hardware, however, was not built into cellular phones until 2009,324 and is still not widely used by many carriers.325 Moreover, even though modern smartphones have the capability to communicate using modern, more secure protocols, they must also be capable to complete calls and function over older cellular networks where older, weaker encryption is still in use. This necessity for backward compatibility is a source of persistent security vulnerabilities. By upgrading the encryption algorithms used by existing second generation (2G) networks or by migrating entirely to more-secure third (3G) and fourth generation (4G/LTE) technologies, wireless carriers can protect their subscribers from the passive interception vulnerabilities described in Part V.B.326 Deutsche Telekom (T- Mobile), for example, has already upgraded its 2G cellular networks in Germany and four other European countries to A5/3, and has planned similar upgrades in other countries (although not yet in the United States).327 Similarly, AT&T has pledged to shut down its 2G network by 2017 in order to repurpose its 2G wireless spectrum for 3G and 4G.328 Alt g AT&T’s pl nned netw k g t n s l kely t v ted by

323 See Matthew Green, On cellular encryption, A Few Thoughts on Cryptographic Engineering, May 13, 2013, http://blog.cryptographyengineering.com/2013/05/a-few-thoughts-on-cellular- enc ypt n. t l (“G M s ne ly 30 ye s ld. You probably wouldn't blame today's Ford execs for the crash performance of a 1982 Ford Escort, and similarly you shouldn't hold the GSM designers

responsible for a 1980s protocol—even f b ll ns f pe ple st ll ely n t.”). 324 See Harald Welte, Structural defic ts n Telc sec ty, P esent t n t Telc ecD y, M c 20, 2012, available at https://www.troopers.de/wp- content/uploads/2011/10/TR12_TelcoSecDay_Welte_Mobsec.pdf, slide 19. 325 In December 2013, two German wireless carriers announced that they were upgrading their networks to support A5/3. When asked about similar upgrade plans by journalists, both AT&T and T- Mobile gave vague, non-committal responses. See Craig Timberg and Ashkan Soltani, By cracking Cellphone Code, NSA Has Capacity for Decoding Private Conversations, Washington Post, December 13, 2013, http://www.washingtonpost.com/business/technology/2013/12/13/e119b598-612f-11e3- bf45-61f69f54fc5f_story.html. 326 More recent cellular phone systems, including so-called 3G and 4G networks, include the capability for phones to authenticate the network base stations. See generally Muxiang Zhang; Yuguang Fang, Security analysis and enhancements of 3GPP authentication and key agreement protocol, Wireless Communications, IEEE Transactions on, vol.4, no.2, pp.734,742, March 2005, available at http://islab.iecs.fcu.edu.tw/GroupMeeting/PowerPoint/20050506_1.pdf. 327 Deutsche Telekom upgrades wiretapping protection in mobile communications, December 9, 2013, http://www.telekom.com/media/company/210108. 328 But see email from Karsten Nohl to Christopher Soghoian, April 21, 2014, on file with author, (“AT&T's announcement to switch off 2G may have been misunderstood. I believe they meant to switch it off where 4G is available as an alternative (urban areas), but I cannot forsee (sic) hundreds of thousands of small 4G cells replacing thousands of 2G cells in rural areas: 2G is the only available technology that allows for large cells.”)

64

consumer demand for high-speed data,329 it will also improve security, because 3G and 4G networks use newer, more secure encryption algorithms. Protecting telephone subscribers from active surveillance devices is not as easy as the network upgrades that will protect subscribers from passive interception. Even when a wireless carrier has upgraded their entire network, the telephones used by their subscribers will still connect to networks that use older, insecure networking technology. This backward compatibility, which is a necessary feature in all handsets because any phone might be taken by its owner to rural areas or foreign countries where older networks remain in use, is a vulnerability that can also be exploited for surveillance.330 Indeed, many of the manufacturers of active surveillance advertise the ability to jam 3G and 4G networks in order to force telephones to connect an active interception device masquerading as a 2G base station.331 The ability to force modern phones to communicate insecurely is an unintended side effect of the need to maintain compatibility for older, insecure cellular network technologies. As long as phones continue to include support for weaker encryption technologies, they can be manipulated into using them, even in a city where all of the legitimate networks use 3G and 4G technology. Protecting against active interception devices will therefore require that new phones no longer include support for older, insecure cellular encryption algorithms, while existing handsets

329 Thomas Gryta, AT&T to Leave 2G Behind, The Wall Street Journal, August 3, 2012, http://onl ne.wsj.c /news/ t cles/ B10000872396390443687504577567313211264588 (“W t every network generation, the technology becomes more efficient at carrying information. As a result, companies can get better and more profitable usage from shutting down older networks in f v f newe nes, s et ng t t AT&T s t lked b t.”) 330 The backward compatibility can be exploited in order to trick 3G and LTE phones into connecting to a 2G IMSI catcher. See Matthew Green, On cellular encryption, A Few Thoughts on Cryptographic Engineering, May 13, 2013, http://blog.cryptographyengineering.com/2013/05/a-few-thoughts-on- cellular-enc ypt n. t l (“T e b ggest s ce f c nce n f 3G/LTE s t t y y n t be s ng t. Most phones are programmed to gracefully 'fail over' to GSM when a 3G/4G connection seems unavailable. Active attackers exploit this feature to implement a rollback attack — jamming 3G/4G connections, and thus re- ct v t ng ll f t e G M tt cks.”). This is not the only vulnerability that can be exploited in backward compatible phones. An active surveillance device can extract the cryptographic keys associated with particular targeted handsets. This cryptographic key material can then be used to either decrypt call data that had been previously recorded and retained, or used in tandem with a passive interception device to perform real-time interception in the future. See Ability Limited (Hong Kong), In-Between Interception System brochure, supra note 39. See also discussion of rollback attacks in supra note 254. 331 See http://www.pki-electronic.com/products/interception-and-monitoring-systems/3g-umts- imsi-c tc e / (“W t 3G UMT IM I C tc e y c n ed ect s ngle UMT b le p nes t specific GSM frequencies, in order to monitor the conversation with our active or passive cellular n t ng syste s.”) ee ls p ge 39 f ttp:// nf .p bl c ntell gence.net/G -GSM.pdf (“T s dev ce w ll e l te 3G netw k t tt ct 3G b les nd, f des gn ted T gets, select vely push them to GSM where they remain unless they are rebooted or pushed back to 3G by the GSM syste .”)

65

will require a software upgrade.332 Obviously, this condition will also entail upgrading all networks where the capacity to complete a wireless call entails use of more primitive and vulnerable technologies like 2G. B. “OVER THE TOP” SOLUTIONS It is possible to deliver secure communications over an insecure network. The HTTPS encryption built into web browsers, which is used to secure data transmitted to and from websites does just that, enabling someone safely to check her bank balance or read her email from a public WiFi network where they would otherwise be vulnerable to WiFi interception.333 Just as the security of Bank of America or G gle’s webs tes d es not depend on their customers’ using secure WiFi networks, so too can the audio and text communications of smartphone users be protected by apps that supply their own encryption, even when the underlying cellular network remains vulnerable to interception. There already exist smartphone ppl c t ns (“ pps”), some with hundreds of millions of existing users,334 w c se enc ypt n t p tect t e se s’ text, v ce, and video communications as they are transmitted over the Internet.335 Examples of

332 Due to the fact that this will mean that these phones will then no longer work in other countries where insecure 2G networks are still used, it may be possible for device manufacturers to offer an opt-in, insecure 2G software setting that can be manually enabled by the device owner if they travel to a foreign country, which will of course leave them vulnerable to interception, but still let them use the network. 333 See Kate Murphy, New Hacking Tools Pose Bigger Threats to Wi-Fi Users, New York Times, supra n. 219. 334 See Matt Swindler, Microsoft highlights 299M Skype users, 1.5B Halo games played, Tech Radar, June 27, 2013, http://www.techradar.com/us/news/software/operating-systems/xbox-live- upgrade-includes-300-000-servers-600-times-more-than-its-debut-1161749. See also Derek Snyder, Skype Passes 100M Android Installs and Launches Redesigned 4.0, Skype Big Blog, June 1, 2013, http://blogs.skype.com/2013/07/01/skype-passes-100m-android-installs-and-launches- redesigned-4-0/ (“Skype for Android is now installed on over 100 million phones worldwide”) See also Daisuke Wakabayashi, Cook Raises, Dashes Hopes for Excitement at Apple Annual Meeting, Wall Street Journal, February 28, 2014, http://blogs.wsj.com/digits/2014/02/28/cook-raises-dashes- hopes-for-excitement-at-apple-annual-meeting/ (“Apple s d t sends ‘seve l b ll n’ messages on its iMessage service every day. Apple said users also send 15 million to 20 million FaceTime messages every day.”). See also Mikey Campbell, Apple sees 2 billion iMessages sent daily from half a billion iOS devices, Apple Insider, January 23, 2013, http://appleinsider.com/articles/13/01/23/apple-sees-2b- imessages-sent-every-day-from-half-a-billion-ios-devices 335 It should be noted that most of these apps do not deliver “end-to-end” enc ypted c n c t ns with keys only known to the communicating parties. T ese se v ces enc ypt t e c st e s’ d t s it is transmitted over the Internet, but that encryption is generally removed once the messages reach t e c p n es’ se ve s. T s, lt g t ese se v ces p tect t e se s’ c n c t ns f unmediated interception via active and passive surveillance devices that exploit cellular network security vulnerabilities, they do not provide wiretap-proof communications. Some apps, however, do ex st t t enc ypt c n c t ns “end-to-end” w t encryption keys that are only known to the parties of the communication, and are neither known, nor accessible to the service provider. As a result, these services not only protect users from the cellular interception vulnerabilities outlined in this Article, but also from government surveillance performed with the help of the wireless carrier, or even the communication service provider itself. Examples of such end-to-end encrypted

66

s c pps ncl de M c s ft’s kype, Apple’s F ceT e nd Mess ge, G gle’s H ng t nd F ceb k’s WhatsApp. These apps use the cellular data network, t e t n t e w eless c e s’ leg cy v ce nd text ess ge syste s, t t ns t content. In many cases, these are available as 3rd party apps that individuals must download from an app store. However, smartphone operating system companies including Apple and Google pre-install their own communications apps on devices running their respective operating systems. In some cases, these apps are even enabled by default and seamlessly encrypt communications without requiring any configuration by the user.336 Communications made using these apps are protected from the cellular interception technology described in this Article.337 Even so, most of these apps do not advertise the security advantages of their services over the legacy telephone network. Instead, they typically compete on cost or ease of use. However, once interception vulnerabilities in our cellular networks become widely known to consumers, these companies with widely used communications apps are well-placed to compete and deliver a more secure communications experience to consumers. VIII. CONCLUSION This Article has illustrated how cellular interception capabilities and technology has become, for better or worse, globalized and democratized, placing Americ ns’ cellular communications at risk of interception by foreign governments, criminals and the tabloid press, to mention a few. Notwithstanding this risk, US government agencies shroud almost every aspect of the StingRay and similar direct interception technology in secrecy in an ostensible but futile effort to prevent criminals from learning how to thwart the technology. But this narrative that disingenuously asserts a continuing need for secrecy regarding StingRay technology does greater

communications services include apps made by Whisper Systems and Silent Circle. See Joshua Lund Fighting DISHFIRE: The State of Mobile, Cross-Platform, Encrypted Messaging (blog post), February 11, 2014, https://missingm.co/2014/02/fighting-dishfire-the-state-of-mobile-cross-platform- encrypted-messaging/ (comparing various encrypted mobile communications apps). 336 F ex ple, s nce 2011, Apple’s O pe t ng syste s sed its own iMessage service for all text messages sent between iOS devices. Such text messages are, without requiring any configuration spec l ct n by t e se , enc ypted nd sent ve t e Inte net s ng Apple’s se ve s, t e t n using the wireless c e ’s text ess ge se ve s. 337 Even when communications are encrypted, it is still possible for a determined adversary (such as a law enforcement or intelligence agency) to intercept those communications. By infecting the end- point (such as a mobile phone or laptop used by one of the callers) with specially designed surveillance software, sophisticated actors can obtain unencrypted audio, video and text communications from t get’s dev ce. US law enforcement and intelligence agencies already use such software. See Jennifer Valentino-DeVries and Danny Yadron, FBI Taps Hacker Tactics to Spy on Suspects, August 3, 2013, http://online.wsj.com/news/articles/SB10001424127887323997004578641993388259674 (“The FBI develops some hacking tools internally and purchases others from the private sector. With such technology, the bureau can remotely activate the microphones in phones running Google Inc's Android software to record conversations, one former U.S. official said. It can do the same to microphones in laptops without the user knowing, the person said.”).

67

harm by inhibiting public awareness and discussion of the risks associated with private use of unmediated surveillance technologies, thus preventing policy makers from addressing the underlying vulnerabilities in cellular networks. In this context, reflexively giving priority to the maintenance of a demonstrably illusory veil of secrecy that allegedly protects the utility of surveillance capabilities over real efforts to protect cellular network security is inconsistent with larger Congressional efforts to strengthen cyber security. If nothing else, the unnecessary and counterproductive veil of secrecy must be lifted so that the public is aware of the interception risks and legislators can addresses them as part of the public policy making process aimed at better, stronger cyber security practices.