Security1 publisher3 min readPublished
Schneier and Cohn trace 25 years of US mass surveillance back to the government's post-9/11 response
Their Lawfare essay says the architecture built after 9/11 now runs largely on data that companies gather for their own business, and it cites FBI Director Kash Patel's testimony that the bureau buys information on Americans from brokers.
The Watch · Security desk

What happened
- Bruce Schneier and Cindy Cohn argue in Lawfare that 9/11 moved the US government from individual wiretaps and pen registers to internet backbone taps and bulk telephone and internet metadata collection.
- The essay says that architecture is now routine law enforcement tooling, with ICE using it in immigration actions and against people exercising their First Amendment rights to protest.
- Private deployments named in the essay include facial recognition at venues such as Madison Square Garden and networked Flock license plate capture on roads and in parking lots.
- The authors say the national security community has never published a cost-benefit analysis of these programs or shown that they stopped an attack other techniques would have missed.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability Every extra field a consumer product retains widens what a law enforcement buyer can obtain later, and it happens under legal authority agencies already have.
- exposure Any operator holding location, plate or behavioural telemetry is a potential collection channel for federal and local agencies, whatever its own policy on responding to legal process says.
- constraint Buying from a broker bypasses the warrant, so the transaction stays clear of the transparency reporting, log review and challenge procedures companies built around court orders.
- precedent A purchasing practice confirmed at director level gives the next agency a stated baseline for buying what it would otherwise have to compel.
Commercial data moves to government through the least regulated step in the chain. Schneier and Cohn wrote that "Surveillance is the business model of the internet," and they put Google and Facebook at the collecting end of it [6]. The consumers are federal and local: the NSA using data gathered by telecommunications and internet companies, sheriffs and ICE agents working from cellphone location data and privately managed automatic license plate readers [7]. Less and less of that access comes through legal process, the essay says [9]. FBI Director Kash Patel confirmed in congressional testimony that the agency is purchasing information on Americans from data brokers and intends to continue, according to the authors [8]. The essay does not give the date of the hearing.
The difference shows up in what a company can see. A court order is a document the recipient can log, challenge, count, and publish in a transparency report. A commercial sale to a broker who later resells to a federal customer produces none of those artifacts at the company that did the collecting. That follows from the essay's own claim: as companies collect more for surveillance capitalism purposes, more becomes available to law enforcement [10].
The 2013 Snowden disclosures included an internal NSA presentation whose stated goals were to "Collect it All," "Process it All," "Exploit it All," "Partner it All," "Sniff it All" and, ultimately, "Know it All" [12]. Partnering is the step the essay now describes running at state and local level, through vendors rather than intelligence liaison [5][7].
The span the authors measure runs from the September 2001 attacks to 2026 [19]. The Snowden material landed at year twelve, which leaves thirteen years since [20]. In that time the national security community has still not produced a full accounting of what these programs cost in taxpayer dollars or diverted resources, and has not demonstrated that the techniques stopped attacks that could not otherwise have been prevented, Schneier and Cohn wrote [13]. When the NSA does offer examples, usually while the programs are under public pressure, the examples regularly fall apart on serious scrutiny, per the essay [14]. The domestic record is thinner still: police and the companies selling the tools float anecdotes and dubious data, and Flock's own figures equate law enforcement hits in its database with crimes solved [15][16].
Schneier and Cohn aim the argument at government policy, and the companies appear in it as suppliers [3]. There is one line in the essay that a security team owns directly. The authors say the problems grow as mass surveillance and analysis technology improves, particularly with wider use of AI [11]. The inventory a product retains is the input to that analysis, and the essay describes a pipeline that carries it from one to the other by purchase [10][8].
It started with telephone records. The essay says the easiest place to see the shift is the government's decision, immediately after 9/11, to collect Americans' call records [18].
What to watch
- Whether Congress or the FBI publishes the broker list and the amounts behind the purchasing Patel confirmed.
- Any independent test of Flock's database-hit metric against actual case closures.
- Whether the national security community answers the essay with the cost-and-benefit accounting it says has never been produced.