by Nathan Smith

In the future (re: today), people won’t dream of having 15 minutes of fame. They’ll dream of getting a glorious 15 minutes of anonymity.

With data centres going up in our backyard, cameras installed on every street and digital IDs smuggled in under the cover of protecting teens from social media, the long-forecasted surveillance state is making a lot of people nervous. Even comedians are starting to joke about it. We should be pushing back against this, right?

Well, I am reminded of the parable of the shoeshine boy. The rule is: if you’re a nobody, then by the time you’ve seen an investment opportunity, it’s too late to do anything about it. Same goes for surveillance. Those cameras and data centres are only the most proximate tip of the iceberg. Most people have no idea how deep the surveillance grid already goes, and how easy it is to track all of us without the need for cameras.

But this topic is not going away. Humans will always be against the idea of making privacy impossible and anonymity effectively a crime. From the perspective of the farmers of men, however, zero privacy makes a lot of sense. After all, they could run the machine much more easily if they knew when a human animal was feeling ill, showing early signs of aggression, or simply hungry. Data can help solve problems, and more data can help solve problems before they become problems.

And like busy little beavers, the farmers of men have slowly but surely constructed their dreamed-of grid. The fences and gates, both digital and analogue, that track, tag, nudge, distract, dangle and train us are as impressive as the pyramids of ancient Egypt. If you could see the surveillance grid, it would surely be one of the wonders of the modern world. And that’s about as neutral as I can be when describing it.

But we should be honest. “Data mining” is a euphemism for spying. If who you are is what you do, then whoever controls the data of what you do will inevitably control you. That’s the goal. The farmers of men are not going to stop just because we protest a few data centres or knock down some cameras. We are far, far beyond the point where any of this can be reversed.

To understand the surveillance grid would require a whole book. All we have time for is a core aspect known as “person-level persistence surveillance.” But it’s the most important aspect since it helps explain why there really is no escaping this wonder of the modern world.

Let’s use one example, the global defence and security company Leonardo. This company has a system called ELSAG SignalTrace, and its job is to collect electronic signals emitted by all kinds of devices. According to the company, its sensors can detect the signals and identify metadata associated with mobile phones, smartwatches, fitness trackers, Bluetooth devices, Wi-Fi sources, RFID tags, vehicle electronics and much more. Then it looks for when these devices often appear together.

Maybe your car contains a particular version of an iPhone, an Audi radio, Bose headphones, a Garmin watch and a key fob. On their own, these devices are boring. But when that exact bundle of devices appears at the same time and place, SignalTrace can turn that bundle into an electronic “fingerprint”. So, even if you remove the number plate on your car, Leonardo will still know it’s your vehicle based on the other signals it receives from the devices all around you.

Of course, there are limits to what its sensors can collect. Many phones randomise their Wi-Fi and Bluetooth addresses to make long-term tracking harder. Devices also vary in how often they broadcast signals and what data they reveal. But researchers have found that some Bluetooth signals remain trackable even when their addresses change because other information in their systems can act as a secondary identifier. Your phone might change its address, but your headphones, watch, car radio and key fob probably won’t, which means the system can infer that the phone’s new signal belongs to the same cluster it saw yesterday.

So, when two or more signals repeatedly appear together, travel along the same route and split off at certain locations, the system knows the owners may be family members, colleagues, neighbours, friends or members of the same organisation. It can then build a pattern of life about those people (known as a “social graph”) without ever hearing them talk or reading their messages. What you do is who you are.

The system isn’t looking for anyone in particular. It’s not trying to solve a crime. Rather, the purpose of person-level persistent surveillance is to collect data all the time, from everyone, because it’s impossible to know which device may become relevant later. When (not if) someone becomes interesting to the farmers of men, it would be highly convenient to know everything about where that person sleeps, where they work, which church they attend, which doctor they visit, who they spend the night with and which political meetings they attend. After all, before you start looking for a needle, you must first create the haystack.

Signals are not private. They are constantly being beamed out from all devices, all day, every day. Leonardo knows how to grab these signals, and there are no laws stopping it from doing so. Again, this is metadata, not texts, phone calls or emails.

The advertising industry has built an entire business around joining these signals. In the trade, they call it identity resolution. Advertising agencies construct their own social graphs that connect (the analogue) names, postal addresses, email addresses and customer records with (the digital) cookies, mobile advertising IDs, “Smart” televisions and IP addresses to generate a unified view of targeted consumers.

My favourite demonstration of this is a piece of software by SilverPush. It allows mobile phones to listen for inaudible codes embedded in normal television audio. A TV can emit a sound above or below the human hearing range but still be picked up by the phone’s microphone. SilverPush’s software can “hear” which advertisement was playing, even if the TV is on mute, and send that data back to the advertisers.

Or have you heard about Facebook’s “shadow profiles”? This is a term for the data created about people who have no Facebook account. How does this work? When Facebook users upload their address books to the site, Facebook will receive the names, phone numbers and email addresses. If ten friends have your number saved under your name, Facebook knows you sit inside ten overlapping social networks without you ever needing to open an account of your own on the platform.

Furthermore, Clearview AI has a facial-recognition database that contains more than 70 billion images gathered from public websites, social media, news reports and other sources. Even if you have never uploaded a single photo of yourself onto the internet, it might be true that a school, employer, sporting club, newspaper or friend has done it for you. One photo can connect an unknown face captured by other cameras to a huge database of names, pages and associations.

Your DNA isn’t safe, either. You may refuse (for good reason) to send your genetic goo to a genealogy company, but it pays to remember that your relatives share parts of your DNA as well. A major 2018 study estimated that about 60% of Americans of European descent could already expect a third-cousin or closer match in a genealogy database. Linking that data to the bundle of all the other data would be child’s play.

By the way, these examples are all from private firms. Governments also collect, but they tend to avoid the more sensitive data that could become a political hot potato if it ever leaked out. Civil servants are sneaky, though. Rather than collect it themselves, governments simply ask private companies for their data. The best thing about this dynamic is that private companies do not have to respond to an Official Information Act request. As I said, civil servants are sneaky.

Hopefully you’re starting to see how it is virtually impossible to hide from person-level persistence surveillance. If the number plate fails, they can use the vehicle’s colour. If the vehicle’s colour changes, use the device bundle. If a device address rotates, use the surrounding devices. If the person leaves their phone at home, use the watch or payment card. If the person never joins Facebook, use their friends’ contacts and photographs. If they never submit DNA, use a cousin. If one company deletes all its data, another copy of that data may be in an advertising company’s databases, a consumer report or a police file.

Person-level persistent surveillance is only one aspect of the enormous surveillance grid being built around us. Every bit of data will be used in some way. Corporations are strip-mining their employees, every consumer product is gathering data, and every public space is turning into a data hunting ground.

But I’ll leave you with one thought. Their surveillance system already knows more about you than you know about you. So, if they know where everyone is, who we are, what we do, and all the other details of our lives, why do they then tell us that deportation of foreigners is impossible?

Why indeed.

Originally published on The Good Oil.

Our Contributor

Share This

Leave A Comment