· via Hacker News – Front Page (native)
Cindy Cohn and Bruce Schneier: 25 years of post-9/11 mass surveillance is enough
Writing in Lawfare 25 years after 9/11, Cindy Cohn and Bruce Schneier argue that mass surveillance has outgrown its counterterrorism justification, and that its costs to rights and effectiveness have never been honestly counted.
.png?sfvrsn=1f2a75b9_7)
The argument
Twenty-five years after the September 11 attacks, two prominent voices on digital rights and security — Cindy Cohn and Bruce Schneier — have published an essay arguing that the era of mass surveillance those attacks unleashed should come to an end. The piece appeared in Lawfare and was reposted on Schneier on Security, and it frames the post-9/11 turn from targeted spying toward bulk collection as a policy shift that has never been honestly measured.
The authors' central charge is that mass surveillance was sold as a temporary necessity against terrorism and quietly became permanent infrastructure. The NSA and, increasingly, ordinary police agencies operate on the assumption that watching everyone everywhere makes the country safer — an assumption, they write, that the national security community has never backed with a genuine cost-benefit analysis, whether in taxpayer dollars, diverted resources, or attacks demonstrably prevented. When the NSA has offered success stories under public pressure, the essay says, those examples tend to fall apart under scrutiny.
How targeted spying became bulk spying
According to the essay, the clearest example is the collection of Americans' telephone records, which began immediately after 9/11 as the "President's Surveillance Program," resting on a claim of raw executive power. In 2006 the government secretly re-based the program on a novel reading of Section 215 of the Patriot Act, a provision that had previously covered more targeted requests. The program was officially confirmed only after Edward Snowden's 2013 disclosures. In 2015 the U.S. Court of Appeals for the Second Circuit rejected that interpretation, and Congress passed the USA Freedom Act the same year, ending indiscriminate bulk collection after nearly 14 years — though, the authors note, the law still permits access to large volumes of domestic phone records.
The NSA's Upstream program, which intercepts metadata and content at major telecommunications junctions inside the U.S., followed a similar path: launched under presidential authority, later brought under limited FISA court review through Section 702 of the 2008 FISA Amendments Act. The agency stopped content searches in 2017 under FISA court pressure, but the bulk collection itself continues. Congress let Section 702 formally lapse in 2026 over concerns about Americans' data being caught in the net, yet previously authorized surveillance runs until at least spring 2027. An internal NSA presentation made public through the Snowden leaks captured the underlying philosophy, the authors write: a government able to "Collect it All," "Process it All," "Exploit it All," "Partner it All" and "Sniff it All" would ultimately "Know it All."
The private pipeline
A recurring theme is that government mass surveillance sits largely downstream of private collection. The NSA relies on data gathered by telecom and internet companies; local sheriffs and ICE agents rely on cellphone location data and privately operated license plate reader networks. FBI Director Kash Patel, the authors note, recently confirmed in congressional testimony that the bureau buys information about Americans from data brokers and intends to keep doing so — access obtained outside traditional legal process. Because the internet's economic model rests on tracking users, whatever companies collect for commercial purposes becomes potentially available to law enforcement as well, and AI-driven analysis is amplifying both the capability and the attendant risks.
Surveillance as a domestic routine
The essay documents how these techniques migrated into everyday life. License plate reader networks from vendors such as Flock and Vigilant Solutions cover public and private roads and parking lots and let officers search across jurisdictions; the authors point to their use in tracking people traveling between states for abortions. Facial recognition, once confined to elite federal units, is now used by ICE against immigrants and protesters, by the TSA in airports, and by private venues such as Madison Square Garden. Smartphones log their users' locations continuously, and that information reaches police with minimal procedural protection. On the industry side, the authors single out Flock for presenting database hits as if they were solved crimes.
Why it matters
Cohn and Schneier are making a constitutional argument as much as a technical one: the Fourth Amendment's protection against unreasonable searches was built around individualized suspicion, and a system that watches everyone by default inverts that principle. They warn that the risks have become more visible under the Trump administration. For technologists, the essay's significance lies in its account of a single continuous pipeline — commercial data collection, data brokers, backbone interception, AI analysis — in which what a product harvests can end up in government hands without a warrant. Twenty-five years on, the authors are asking for something basic: an actual accounting of whether any of this makes people safer, and what it has cost in rights and freedoms.
- #surveillance
- #privacy
- #security
- #policy
- #civil-liberties