Rantburg

Today's Front Page   View All of Thu 05/02/2024 View Wed 05/01/2024 View Tue 04/30/2024 View Mon 04/29/2024 View Sun 04/28/2024 View Sat 04/27/2024 View Fri 04/26/2024
2022-12-03 Government Corruption
A Peek Inside the FBI's Unprecedented January 6 Geofence Dragnet
[Wired] Google provided investigators with location data for more than 5,000 devices as part of the federal investigation into the attack on the US Capitol.

The FBI’s biggest-ever investigation included the biggest-ever haul of phones from controversial geofence warrants, court records show. A filing in the case of one of the January 6 suspects, David Rhine, shows that Google initially identified 5,723 devices as being in or near the US Capitol during the riot. Only around 900 people have so far been charged with offenses relating to the siege.

The filing suggests that dozens of phones that were in airplane mode during the riot, or otherwise out of cell service, were caught up in the trawl. Nor could users erase their digital trails later. In fact, 37 people who attempted to delete their location data following the attacks were singled out by the FBI for greater scrutiny.

Continued from Page 6



Geofence search warrants are intended to locate anyone in a given area using digital services. Because Google’s Location History system is both powerful and widely used, the company is served about 10,000 geofence warrants in the US each year. Location History leverages GPS, Wi-Fi, and Bluetooth signals to pinpoint a phone within a few yards. Although the final location is still subject to some uncertainty, it is usually much more precise than triangulating signals from cell towers. Location History is turned off by default, but around a third of Google users switch it on, enabling services like real-time traffic prediction.

The geofence warrants served on Google shortly after the riot remained sealed. But lawyers for Rhine, a Washington man accused of various federal crimes on January 6, recently filed a motion to suppress the geofence evidence. The motion, which details the warrant’s process and scale, was first reported by journalist Marcy Wheeler on her blog, Emptywheel.

In a statement, a Google spokesperson defended the company’s handling of geofence warrants.

“We have a rigorous process for geofence warrants that is designed to protect the privacy of our users while supporting the important work of law enforcement,” the company said. “When Google receives legal demands, we examine them closely for legal validity and constitutional concerns, including overbreadth, consistent with developing case law. If a request asks for too much information, we work to narrow it. We routinely push back on overbroad demands, including overbroad geofence demands, and in some cases, we object to producing any information at all.”

Google requires a three-step process for geofence warrants to narrow their scope to only those most likely to be guilty of a crime. In the first and broadest step, the FBI asked Google to identify all devices in a 4-acre area, including the Capitol and its immediate surroundings, between 2 pm and 6:30 pm on January 6. Google initially found 5,653 active devices that “were or could have been” within the geofence at that time. When Google added in data from devices that only connected to its servers later that day, or the next, the number increased to 5,723. (Location History works in airplane mode because phones can continue to receive GPS satellite signals.)

In the second step, the FBI asked Google for a list of devices that were present at the Capitol from 12 pm to 12:15 pm on January 6, and from 9 pm to 9:15 pm. As there were no rioters in the Capitol during those times, these devices likely belonged to congressional members or staff, police, and other people authorized to be there. Over 200 such phones were excluded from the initial list, reducing its total to 5,518.

For the final step, the government sought subscriber information, including phone numbers, Google accounts, and email addresses, for two groups of users. The first was for devices that appeared to have been entirely within the geofence, to about a 70 percent probability. The second was any devices for which the Location History was deleted between January 6 and January 13.

From this, in early May 2021, the FBI received identifying details for 1,535 users, as well as detailed maps showing how their phones moved through the Capitol and its grounds. Geofence evidence has so far been cited in over 100 charging documents from January 6. In nearly 50 cases, geofence data seems to have provided the initial identification of suspected rioters.

Rhine was first flagged to the FBI by tipsters who had heard that he had been inside the Capitol. But investigators only identified him in surveillance footage after they matched it against the precise geofence coordinates of his phone. His lawyer is now trying to get the geofence evidence thrown out on a number of grounds, including that it was overly broad in who it rounded up, and that Rhine had a constitutional expectation of privacy in his Google data.

“The government enlisted Google to search untold millions of unknown accounts in a massive fishing expedition,” the attorneys wrote. “Just a small amount of Location History can identify individuals … engaged in personal and protected activities (such as exercising their rights under the First Amendment). And as a result, a geofence warrant almost always involves intrusion into constitutionally protected areas.”

If the judge tosses the geofence evidence in the Rhine case, there is a chance that he and other suspects identified using it could walk free.

The FBI’s biggest-ever investigation included the biggest-ever haul of phones from controversial geofence warrants, court records show. A filing in the case of one of the January 6 suspects, David Rhine, shows that Google initially identified 5,723 devices as being in or near the US Capitol during the riot. Only around 900 people have so far been charged with offenses relating to the siege.

The filing suggests that dozens of phones that were in airplane mode during the riot, or otherwise out of cell service, were caught up in the trawl. Nor could users erase their digital trails later. In fact, 37 people who attempted to delete their location data following the attacks were singled out by the FBI for greater scrutiny.

Geofence search warrants are intended to locate anyone in a given area using digital services. Because Google’s Location History system is both powerful and widely used, the company is served about 10,000 geofence warrants in the US each year. Location History leverages GPS, Wi-Fi, and Bluetooth signals to pinpoint a phone within a few yards. Although the final location is still subject to some uncertainty, it is usually much more precise than triangulating signals from cell towers. Location History is turned off by default, but around a third of Google users switch it on, enabling services like real-time traffic prediction.

The geofence warrants served on Google shortly after the riot remained sealed. But lawyers for Rhine, a Washington man accused of various federal crimes on January 6, recently filed a motion to suppress the geofence evidence. The motion, which details the warrant’s process and scale, was first reported by journalist Marcy Wheeler on her blog, Emptywheel.

In a statement, a Google spokesperson defended the company’s handling of geofence warrants.

“We have a rigorous process for geofence warrants that is designed to protect the privacy of our users while supporting the important work of law enforcement,” the company said. “When Google receives legal demands, we examine them closely for legal validity and constitutional concerns, including overbreadth, consistent with developing case law. If a request asks for too much information, we work to narrow it. We routinely push back on overbroad demands, including overbroad geofence demands, and in some cases, we object to producing any information at all.”

Google requires a three-step process for geofence warrants to narrow their scope to only those most likely to be guilty of a crime. In the first and broadest step, the FBI asked Google to identify all devices in a 4-acre area, including the Capitol and its immediate surroundings, between 2 pm and 6:30 pm on January 6. Google initially found 5,653 active devices that “were or could have been” within the geofence at that time. When Google added in data from devices that only connected to its servers later that day, or the next, the number increased to 5,723. (Location History works in airplane mode because phones can continue to receive GPS satellite signals.)

In the second step, the FBI asked Google for a list of devices that were present at the Capitol from 12 pm to 12:15 pm on January 6, and from 9 pm to 9:15 pm. As there were no rioters in the Capitol during those times, these devices likely belonged to congressional members or staff, police, and other people authorized to be there. Over 200 such phones were excluded from the initial list, reducing its total to 5,518.

For the final step, the government sought subscriber information, including phone numbers, Google accounts, and email addresses, for two groups of users. The first was for devices that appeared to have been entirely within the geofence, to about a 70 percent probability. The second was any devices for which the Location History was deleted between January 6 and January 13.

From this, in early May 2021, the FBI received identifying details for 1,535 users, as well as detailed maps showing how their phones moved through the Capitol and its grounds. Geofence evidence has so far been cited in over 100 charging documents from January 6. In nearly 50 cases, geofence data seems to have provided the initial identification of suspected rioters.

Rhine was first flagged to the FBI by tipsters who had heard that he had been inside the Capitol. But investigators only identified him in surveillance footage after they matched it against the precise geofence coordinates of his phone. His lawyer is now trying to get the geofence evidence thrown out on a number of grounds, including that it was overly broad in who it rounded up, and that Rhine had a constitutional expectation of privacy in his Google data.

“The government enlisted Google to search untold millions of unknown accounts in a massive fishing expedition,” the attorneys wrote. “Just a small amount of Location History can identify individuals … engaged in personal and protected activities (such as exercising their rights under the First Amendment). And as a result, a geofence warrant almost always involves intrusion into constitutionally protected areas.”

If the judge tosses the geofence evidence in the Rhine case, there is a chance that he and other suspects identified using it could walk free.

Matthew Tokson, a law professor and Fourth Amendment expert at the University of Utah, says there remains a high level of uncertainty around the whole idea of geofence warrants: “Some courts have said they are valid. Some have said they are overbroad and sweep up too many innocent people. We are still in the very early stages of this.”

Despite the unprecedented number of individuals swept up in the January 6 search warrant and some strong arguments from Rhine’s lawyer, Tokson thinks the chance of his motion succeeding is very low. “Unlike a geofence warrant for a bank robbery, the people in this location are all likely to be engaged in at least a low-level criminal trespass and in some cases worse,” he says. “There’s a stronger than usual probable cause argument in favor of the government here.”

Andrew Ferguson, a professor of law at American University, agrees. “And that worries me because the January 6 cases are going to be used to build a doctrine that will essentially enable police to find almost anyone with a cellphone or a smart device in ways that we, as a society, haven’t quite grasped yet,” he says. “That is going to undermine the work of journalists, it’s going to undermine political dissenters, and it's going to harm women who are trying to get abortion services.”

The judge is likely to rule on Rhine’s motion in December, with his trial scheduled for late January 2023. While that will decide Rhine’s fate, it is unlikely to settle the question of geofence warrants more broadly. “This very likely will be appealed one way or the other,” says Tokson. “It’s going to be a very high-level, high-profile case likely to generate a major precedent out of the appeals court, if not the Supreme Court.”
Posted by Skidmark 2022-12-03 00:00|| || Front Page|| [15 views ]  Top
 File under: Mob Rule 

#1 No thought given by the Bureau to the future impacts on discovery involving criminal activity here or OCONUS. They were just going for the 'big win' and hoping no one would find out about their 'sources and methods.'

Global Tracking Systems (GTS) like GEOFENSE have been around for decades.
Real criminals and terrorists use burner phones (throw aways). If they don't now, they certainly will in the future. What a bunch of dumb asses.

The gov't and FBI will likely get away with the use of GEOFENCE. Federal judges and the courts will NOT want to open up the can of worms (beyond GEOFENCE) that GOOGLE cooperation with the gov't and intelligence community likely represents. Insert 'National Security Concerns' here.

The potential revelation that GOOGLE, FB, and the former Twitter platforms, and others, are actually US gov't funded tools would be very bad for business.....both here, and abroad.

How can anyone now assume otherwise? I mean it is a 'Police State' for non-Democrats right ?

Posted by Besoeker 2022-12-03 01:01||   2022-12-03 01:01|| Front Page Top

#2 I imagine if they want to claim they detected your phone in the target area, it does not matter where you actually were during the time frame in question.
Posted by M. Murcek 2022-12-03 08:46||   2022-12-03 08:46|| Front Page Top

#3 How many FBI phones turned up in this dragnet?
Posted by Abu Uluque 2022-12-03 11:31||   2022-12-03 11:31|| Front Page Top

#4 How many FBI phones turned up in this dragnet?

Geeze. The block of phone numbers assigned to the gummint don't even register in the data searches. Can you say "Area Code 000 kids? I knew ya could..."
Posted by M. Murcek 2022-12-03 11:54||   2022-12-03 11:54|| Front Page Top

#5 1st rule of Protest Club
Never bring your Smart Phone to the event.

Remember to activate away from home.

Remove battery when not in use or within miles of home or work.
Posted by NN2N1 2022-12-03 12:45||   2022-12-03 12:45|| Front Page Top

#6 I remember when we had a Constitution before Nicholas Cage stole it.
Posted by Super Hose 2022-12-03 12:45||   2022-12-03 12:45|| Front Page Top

#7 
Remove battery when not in use or within miles of home or work.

Can't remove my smartphones's battery without destroying the phone.
Posted by Elmaper McGurque1612 2022-12-03 21:54||   2022-12-03 21:54|| Front Page Top

23:36 Skidmark
23:32 Skidmark
21:17 trailing wife
20:38 swksvolFF
20:12 AlmostAnonymous5839
20:07 Frank G
20:05 Frank G
20:03 Frank G
19:59 swksvolFF
19:49 Huputle+Cherelet4131
19:42 Jack Salami
19:36 Jack Salami
19:34 Glenmore
19:17 Glenmore
19:15 Glenmore
18:41 Frank G
18:26 swksvolFF
18:18 Whiskey Mike
17:46 Deacon+Blues
17:42 Deacon+Blues
17:31 Deacon+Blues
17:20 Old Patriot
17:16 trailing wife
17:10 trailing wife









Paypal:
Google
Search WWW Search rantburg.com