Back to Home
Security

US courts will start publishing how often the government uses spyware

The Administrative Office of the U.S. Courts told TechCrunch that it will start disclosing how many times judges authorized the use of spyware to wiretap suspected criminals.

t
tech4you AI
August 14, 20264 min read
Share

The FBI has been using hacking techniques and tools, such as spyware, since at least 1998, but to date there is no public data counting how often the feds were deploying them. That’s about to change — at least for the use of spyware for tapping into someone’s real-time communications.

Starting in 2029, U.S. judiciary will publicly disclose precisely how many times judges authorized the use of wiretaps to be carried out with hacking tools and spyware, which fall under the category of what the feds call network investigating techniques, or NITs.

For almost two decades, the Administrative Office of the U.S. Courts, which coordinates operations across the judiciary, has issued annual Wiretap Reports. These reports detail how many wiretaps were authorized every year, breaking the numbers down by whether federal or state judges ordered them, in which states the wiretaps were conducted, what type of crime was investigated, and other data. 

Wiretaps allow police to gain real-time access to people’s calls, messages, and other communications. Given how invasive wiretaps can be to a person’s privacy, law enforcement have to present a high bar of evidence that a crime is being committed before a judge will authorize the use of a live tap. As such, wiretaps are generally issued in far fewer numbers than search warrants, but can still sweep up a large amount of people’s communications. Years ago, for example, one wiretap allowed a massive surveillance operation that collected millions of text messages over the course of three months.

The annual wiretap reports break down the type of wiretaps authorized during the year: from audio wiretaps that can collect real-time voice from phone calls; oral taps that rely on using real-world microphones and other eavesdropping techniques; and, the electronic tapping of text messages, emails, and other messages as they pass through a provider’s network.

The Administrative Office of the U.S. Courts told Democratic senator Ron Wyden this week that it will begin tracking the new “spyware/hacking” surveillance category starting in the 2028 Wiretap Report, which will be published the following year. 

A spokesperson for the Administrative Office of the U.S. Courts confirmed the change in an email to TechCrunch: “The Wiretap Report is compiled from individual forms submitted from throughout the country and throughout the year. Before the new data can appear in the annual report, reporting forms and procedures need to be updated to accommodate the new categories,” the spokesperson said. 

It’s important to note that this statistic will only reveal when authorities have used spyware to intercept communications, such as Signal and WhatsApp calls and messages, and not when they use tools to remotely hack into a phone and extract data stored inside of it, such as images, files, and their location. The first is a wiretap, and the latter is a search, which is an altogether different kind of legal process and not relevant here.

Wyden, who has criticized “the unnecessary secrecy around electronic surveillance orders” and has called for this kind of data to be published since 2017, celebrated the change.

“The American people remain largely in the dark about the different ways that the government is spying on them,” Wyden said in a statement to TechCrunch. “I am thankful that the federal courts agreed to collect and publish data about hacking, but Congress must go further and pass my Government Surveillance Transparency Act,” a draft bill that Wyden and others reintroduced earlier this year.

Getting this kind of transparency, according to privacy experts, is a huge win.

“Up until now, we have only been able to guess at the size of the problem,” said Eva Galperin, the director of cybersecurity at the Electronic Frontier Foundation and an expert on government spyware. 

Galperin said that once these statistics become public, it will help hold the U.S. government accountable when there are abusive uses of spyware, as it will be harder for the authorities to deny that the tools were used. 

“Being able to point to a report saying that spyware was used X number of times will help with accountability, especially if it turns out that number is quite high,” Galperin added. “It’s hard to say that you’re using spyware as a surgical tool when you’ve deployed it tens of thousands of times.”

Brett Max Kaufman, a senior counsel in the American Civil Liberties Union’s Center for Democracy, said the change is “an important and long-overdue step forward for transparency around government hacking and should lead to better-informed policy and law around these issues going forward.”

Other countries, such as Italy, already publish detailed data on the use of spyware. For example, in 2023, spyware was used against 4,321 targets in the country, according to publicly available data.


Originally published on TechCrunch

US courts will start publishing how often the government uses spyware | tech4you