US Capitol dome silhouetted against an overcast sky at dawn
Photo via Unsplash

Today in Surveillance:

  • FISA 702: 4 days to expiration. Senate returns today. The procedural vote failed Friday 47-52. Cotton and Grassley are now asking Sec. Rubio to plan a "fallback executive order" for a "potential significant gap in foreign intelligence collection." The math hasn't changed since Friday. The path forward still requires either a Pulte-free vehicle, a clean short-term extension, or letting the statute lapse on autopilot under FISA Court certifications [1][2][3].
  • FROST confirmed: your hard drive is now a browser side channel. Researchers at Graz University revealed that a web standard (OPFS) lets any website measure SSD activity through timing analysis and reconstruct what apps and sites you're running. Every browser vendor was told. Every browser vendor said: not a bug, working as designed [4][5][6][7].
  • Citizen Lab's Webloc investigation is now an NPR series. The April report on Penlink's ad-bid-based geolocation surveillance has been syndicated across 15+ NPR stations. 500 million devices. Used by ICE, DHS, LAPD, NYPD. No warrant required. Sen. Wyden and 70 Democrats have called for a federal investigation [8][9][10][11].
  • Maryland grocery pricing ban: 116 days to October 1. HB 895 takes effect in four months. Connecticut signed its twin law Friday. The state of play: which grocery chains are already testing dynamic pricing, and what the loyalty-card loophole looks like [12].
  • DOGE/SSA primer: the "largest data breach in our nation's history." A March whistleblower disclosure alleged a DOGE operative copied 548 million SSA records to a thumb drive and a cloud environment with no audit trail. House Democrats are calling for a criminal investigation. If you have a Social Security number, the practical steps are: credit freeze, IRS IP PIN, E-Verify Self Lock [13][14][15][16][17].
  • Mid-year surveillance check: five threats that aren't going away. FISA's collapse. DOGE's data grab. ShinyHunters' 1.8 billion records. Meta's facial-recognition code shipping in millions of Ray-Ban glasses. Age verification as the default. Halfway through 2026, none of it is getting better on its own [18].
  • Weekend breach watch: Meta AI chatbot hijacked 20,225 Instagram accounts. A flaw in Meta's AI support chatbot let anyone reset the password of any Instagram account without 2FA, including the dormant Obama White House handle. Meta took seven weeks to fix it [19].

FISA 702: 4 Days to Expiration. Senate Reconvenes Today.

The Senate returns Monday morning with four working days to reauthorize FISA Section 702 before the June 12 expiration, and a Friday procedural vote that failed 47-52 [1][2][3].

Seven Republicans joined every Democrat except Sen. Fetterman in voting against cloture. The sticking point was the Trump administration's decision to install Bill Pulte (a former Federal Housing Finance Agency director with no intelligence-community experience) as acting Director of National Intelligence. Senate Democrats and the seven Republicans refused to hand the warrantless surveillance program to someone they view as unaccountable [1][3].

The new wrinkle over the weekend: Sens. Tom Cotton (R-Ark.) and Chuck Grassley (R-Iowa) sent a letter to Secretary of State Marco Rubio asking the State Department to "begin planning for a fallback executive order" to address what the letter calls a "potential significant gap in foreign intelligence collection" if Congress fails to reauthorize by June 12. The letter, first reported by CBS News, is the first explicit signal from Senate Republican leadership that the administration is preparing to bypass Congress on Section 702 [1].

That sets up a legal flashpoint on the far side of any expiration. An executive order cannot create new FISA Court certifications or extend existing ones; those require statutory authority. What it can do is direct the intelligence community to continue collection under other authorities (Executive Order 12333, National Security Letters) and to share the resulting data with the FBI and DHS using looser minimization rules. The "gap" Cotton and Grassley are planning for is, in practice, a gap in oversight, not a gap in collection [1][2]. For the background on what Section 702 actually authorizes, see our explainer on the reauthorization debate.

Even if the statute lapses Friday, the FISA Court's existing certifications keep ongoing 702 collection running until as late as April 2027. The "expiration" is more political theater than operational reality, which is exactly why reformers are trying to use the deadline as leverage, and exactly why Cotton and Grassley are trying to plan around it [1][2][3].

What the math looks like for the rest of the week:

  • Monday, June 8: Senate reconvenes. Watch for Majority Leader Thune's opening move: a procedural re-vote (same math problem as Friday), a Pulte-free vehicle, or a one-week extension. The procedural re-vote has the same 47-52 problem, so don't bet on it succeeding.
  • Tuesday–Wednesday, June 9–10: Negotiations. If Warner and Cotton can find a face-saving vehicle (maybe a clean two-week extension, maybe a deal that ties Pulte withdrawal to the vote) the math might move. Warner privately asked Thune to pressure Trump to withdraw the Pulte nomination. It hasn't happened yet.
  • Thursday, June 11: Last realistic day for a clean vote. After this, the math forces either a weekend session or a short-term extension.
  • Friday, June 12: Statutory expiration. FISA Court certifications carry collection forward. The "expired" headline is more political than operational.

Related: FISA 702: Senate Vote Fails 47-52, 5 Days to Expiration | FISA 702: What Actually Stops, and What Doesn't | 2026 Mid-Year Surveillance State: Five Threats That Defined the First Half

FROST Confirmed: Your Hard Drive Is Now a Browser Side Channel

Researchers at Graz University of Technology publicly released FROST on Friday: a working attack that lets any website measure SSD activity through a web standard called the Origin Private File System (OPFS) and reconstruct what apps and sites you're running on the same machine [4][5][6][7].

The attack is technically elegant and operationally simple. OPFS gives web apps fast, sandboxed storage. A web page can write small files to OPFS and measure how long each write takes. The timing varies depending on what else the SSD is doing, and that "what else" includes every other app and site running on the same physical drive. A trained neural network can read the timing signatures and tell whether you have Signal Desktop open. Whether you have 1Password running. Whether you're in the middle of a Tor Browser session. The model recognizes dozens of common apps and sites in real time [4][5].

The Graz team disclosed the attack to Google, Mozilla, and Apple before going public. All three responded, and all three said roughly the same thing: this is a working-as-intended use of a web standard, not a security bug [4][6].

That's the part that should make you angry. OPFS was designed to give web apps fast, private storage. Using it to measure SSD timing isn't a security bug in the OPFS spec. It's an unintended side effect of OPFS sharing a physical drive with everything else. There's no clean fix that wouldn't break legitimate OPFS apps, and the browser vendors aren't going to break a working web standard to plug a side channel that affects "only" fingerprinting [4][6].

Sound familiar? It's the same playbook as the EFF's confirmed facial-recognition code shipping in millions of Meta Ray-Ban glasses, the FARSIGHT drone gait-recognition research, and the long history of audio-context and canvas fingerprinting. When the web platform builds a powerful feature, advertisers and surveillance operators find a way to use it for tracking. The platform owners shrug [4][6][7].

The Graz team is presenting FROST at the DIMVA conference in July 2026. That gives browser vendors roughly a month to change their minds. The betting line is they won't [4].

What you can actually do: Use Tor Browser for sensitive browsing (OPFS disabled by default). Run sensitive apps in a separate browser profile or on a different machine. Use a VM with its own virtual SSD for untrusted browsing. Or disable OPFS in browser flags (Chrome: chrome://flags/#file-system-access-api → Disabled; Firefox: about:configdom.fs.enabled → false; Safari: Develop menu → Experimental Features → uncheck "OPFS"). You'll break some web apps, but you'll also close the side channel [4].

Related: FROST SSD Side-Channel Attack: The Full Technical Breakdown | Canvas Fingerprinting Explained | FARSIGHT Drone Gait Recognition

Citizen Lab's Webloc Investigation Is Now an NPR Series

Citizen Lab's April 2026 report on Penlink's Webloc (a system that turns advertising bid-stream data into a 500-million-device geolocation surveillance tool) is having a second life as an NPR investigation syndicated across 15+ member stations [8][9][10][11].

Webloc works by exploiting the real-time bidding (RTB) infrastructure that runs the modern ad industry. Every time an ad loads on your phone, your device broadcasts your location, device ID, and a stack of behavioral signals to dozens of ad exchanges in an auction that takes about 200 milliseconds. Webloc doesn't need to break into the ad exchanges. It is an ad exchange, or, more precisely, it sits on top of one. Penlink, the same company that sells the phone-tracking platform ICE and the DEA use to build geofence warrants, has been quietly operating the Webloc surveillance product alongside its more visible law-enforcement business [8][9][11].

The Citizen Lab report documented Webloc use by:

  • U.S. law enforcement: LAPD, NYPD, ICE, DHS, Customs and Border Protection, and the DEA, per the report's review of procurement documents, court filings, and Pitchbook entries.
  • U.S. military: The report identifies "special operations and intelligence customers" but does not name specific units.
  • Foreign intelligence and law enforcement: Hungary's government, per a parallel VSquare investigation, has used Webloc to monitor political opponents, journalists, and civil-society figures, a deployment that almost certainly violates the EU's GDPR [8][9][11].

None of these deployments require a warrant. The argument, such as it is, is that the data is "anonymized" because the device IDs in the bid stream aren't tied to names. They are tied to device IDs, which are tied to SIMs, which are tied to accounts. The "anonymization" is a fig leaf, and the court system has been pushing back. A growing number of U.S. judges are requiring warrants for Webloc-derived location data, and the Fourth Circuit heard oral arguments last month on a case that could set a national rule [8][9][10].

Sen. Ron Wyden (D-Ore.) and 70 House Democrats have called for a federal investigation into ICE and DHS's warrantless purchases of Americans' location data, including through Webloc and similar products. The letter, sent in March 2026, has not yet received a public response from the Department of Homeland Security [10].

Related: Your Weather App Is a Government Spy: How Ad Data Tracks 500 Million Phones for Police | How Ad Bidding Became a Government Surveillance Pipeline | ICE's Webloc Use: What We Know | CBP Border Device Searches: EFF's Fourth Circuit Brief

DOGE Has Your Social Security Data. Here's the Consumer-Facing Version.

If you have a Social Security number, the March 2026 whistleblower disclosure about DOGE's handling of SSA data matters to you personally. Here's what actually happened, and what you can actually do [13][14][15][16][17].

The disclosure: a former DOGE team member filed a sworn declaration with the Office of Special Counsel alleging that a DOGE operative copied approximately 548 million records from two restricted SSA databases (the Numident, a comprehensive record of every Social Security number ever issued, and the Master Death File) and stored the data in a cloud environment with no audit trail and no access controls. The disclosure was first reported by The Washington Post on March 10, 2026, and corroborated by NPR on March 11 [14][15].

The data set, if the allegations hold, includes every Social Security number ever issued, every name associated with that number, every date of birth, every place of birth, every death record, and the parent-child links that connect them. It is, functionally, the master key to identity verification in the United States. House Democrats have called it "the largest data breach in our nation's history" [15][16].

The status: a federal judge initially blocked DOGE's Treasury access, the appeals court reversed, and in January 2026 the U.S. Supreme Court ruled 6-3 that DOGE could access Social Security data. The data they copied is still out there, somewhere, on infrastructure no one outside the DOGE circle can audit. The 19-state lawsuit originally filed in February 2025 is still winding through the courts [15][16]. The copied records also feed the cross-agency master database DOGE is building with Palantir.

What to do (practical, no politics):

  1. Freeze your credit at all three bureaus. Equifax, Experian, TransUnion. It's free, it's reversible, and it's the single most effective step you can take to prevent new-account fraud using your Social Security number. The FTC has a step-by-step guide [16].
  2. Get an IRS Identity Protection PIN. An IP PIN is a six-digit number the IRS requires on every tax return tied to your SSN. Without it, a fraudster can't file a return in your name. It's free and available to anyone who's verified their identity at IRS.gov [16].
  3. Lock your E-Verify account. E-Verify's Self Lock feature lets you prevent anyone from using your SSN for employment verification, a key step in the work-authorization fraud that the DOGE exposure most directly enables [16].
  4. Set up a my Social Security account if you don't already have one. Creating an account prevents a fraudster from creating one in your name and redirecting your benefits. SSA has been the target of an ongoing account-takeover campaign since 2024 [16].
  5. Watch for SSA "no-change" direct deposit mailings. The most common post-DOGE fraud pattern is a Social Security direct-deposit redirect. If you get a "no-change" letter from SSA saying your direct deposit information has been updated, and you didn't update it, call SSA immediately at 1-800-772-1213 [16].

Related: DOGE Social Security Data Breach: The Whistleblower Disclosure | DOGE Has Your Social Security Data. Here's What You Can Actually Do About It. | The DOGE/SSA/Voter Data Scandal Explained

Maryland's Grocery Pricing Ban: 116 Days to October 1

Maryland's HB 895, the country's first state-level ban on personalized grocery pricing, takes effect October 1, 2026. Connecticut signed a similar law Friday. The two states are now four months from a regulatory shift that could end the loyalty-card-as-surveillance-infrastructure business model that Kroger, Albertsons, and Ahold Delhaize have been quietly building for the last decade [12].

The core question, for shoppers, is whether dynamic pricing is already happening at your store. The answer, in most cases, is yes, but it's been hidden in the loyalty card data layer. Yesterday's shopper guide walked through the five tests you can run on your local store: scan a loyalty card and a non-loyalty card for the same item, check electronic shelf labels for price changes, compare prices across stores, watch for "personalized" coupons in your app, and time purchases around known demand spikes [12].

The next question, for the next 116 days, is which chains are already preparing to comply, and which are going to test the law. The likely scenarios:

  • Big chains will comply on shelf prices and test the loyalty-card-data loophole. HB 895 bans the use of personal data to set prices at the register. It doesn't (yet) ban the collection of that data through loyalty programs. Expect Kroger and Albertsons to keep their data pipelines running and shift the dynamic-pricing experiments off-store into "personalized" digital coupons delivered through their apps.
  • Independent stores will mostly comply by default. They don't have the data infrastructure to do personalized pricing at scale. HB 895's main effect on independents is removing the competitive disadvantage of not doing it.
  • The real fight is at the data-broker layer. If the chains can't price-discriminate in-store, they'll sell the data they were going to use for pricing to the highest-bidding data broker instead. The Connecticut SB 4 deletion portal and the Maryland AG's enforcement actions will be the places to watch for that fight.

Related: Maryland's Grocery Pricing Ban: What Changes for Shoppers | Connecticut's SB 4: The Full Breakdown | Pallone's 25-Retailer Investigation

Mid-Year Check: Five Threats That Aren't Going Away on Their Own

Sunday's mid-year surveillance recap walked through the five structural shifts that have defined 2026. None of them are getting better on their own. Quick summary, with the underlying dynamics [18]:

  1. Warrantless surveillance is on life support, and that's the best-case scenario. FISA Section 702 is collapsing. The Senate's Friday 47-52 vote is the first time a Section 702 reauthorization had to clear a public bipartisan revolt. Even if the statute expires Friday, the FISA Court's existing certifications keep collection running until April 2027. The "collapse" is political, not operational, but the political collapse is the lever reformers have been waiting for [1][2][3][18].
  2. DOGE has your data. There's no plan to give it back. The original access has not been revoked. DOGE teams are still embedded at SSA, Treasury, HHS, and the Department of Education. The data they copied is still out there, somewhere, on infrastructure no one outside the DOGE circle can audit. The 19-state lawsuit and the AARP-driven criminal investigation referral are the only formal accountability channels in play [13][14][15][16][18].
  3. ShinyHunters have stolen 1.8 billion records. They're not done. The 2026 extortion campaign is the largest coordinated data-laundering operation in history. ADT, Aflac, Allianz, Adobe, AdvancedHealth, ESAs, and dozens of other breaches are now in the group's "for sale" inventory. The consumer-facing risk is identity-theft-driven synthetic-account fraud at a scale that outstrips the credit bureau fraud-detection stack [18].
  4. Meta's smart glasses already have facial recognition. They just haven't turned it on. EFF's Threat Lab used static code analysis to confirm the "Name Tag" feature (which converts faces into 2,048-number faceprint arrays) is already deployed in millions of Meta Ray-Ban glasses. A researcher activated it in debug mode. The code is live, just not turned on yet. We broke down how the Name Tag faceprinting works in detail. The April 6 deadline for Meta's facial-recognition response from the Senate has passed with no public answer [18].
  5. Age verification is the surveillance creep of 2026. Louisiana's law took effect June 1. Half of U.S. states now mandate some form of age verification. The infrastructure being built to verify age is the same infrastructure that can be used to track users across the open web. EFF's "privacy nightmare" analysis is the clearest breakdown of the risks [18].

Related: 2026 Mid-Year Surveillance State: The Full Five-Threat Breakdown

Weekend Breach Watch: Meta AI Chatbot, Maryland Grocery, and What Else Got Hit

Three stories from the weekend that surveillance readers should know about [19][20][12].

Meta AI Chatbot: 20,225 Instagram accounts hijacked. A flaw in Meta's AI support chatbot let anyone reset the password of any Instagram account that didn't have two-factor authentication. Between April 17 and early June 2026, attackers ran off with short usernames, the dormant Obama White House handle, and the account of a Space Force chief master sergeant. Meta took seven weeks to fix it. The high-profile victims made the news. The other 20,000 didn't [19].

Maryland Grocery Pricing: 116 Days Out. The first state-level ban on personalized grocery pricing is four months from going live. The compliance question (what chains are already testing dynamic pricing, and what the loyalty-card loophole looks like) is the next big consumer-surveillance story [12].

EFF's "Mass Surveillance Tech Is Losing": A Counter-Narrative. The EFF published a Tuesday piece cataloging recent wins against facial recognition, ALPR, and AI surveillance deployments. Cities that said no. Schools that paused. Laws that passed. It's a useful counter-narrative to the "surveillance is inevitable" story, and a fundraising pitch through mid-June [20].

What to Watch

  • Monday, June 8: Senate reconvenes. Watch for Thune's opening move on FISA 702. The procedural re-vote has the same 47-52 math problem. The Cotton-Grassley fallback letter to Rubio is the new live wire: an executive order on Section 702 would be the next surveillance-law flashpoint [1][2][3].
  • Tuesday–Wednesday, June 9–10: FISA 702 negotiations. If Warner and Cotton can find a face-saving vehicle, the math might move. If they can't, expect a short-term extension request by Thursday, the kind of punt that kicks the deadline to early July and sets up an August fight.
  • Thursday, June 11: Last realistic day for a clean FISA 702 vote. After this, the math forces either a weekend session or a short extension. Also watch for the EFF's mid-year fundraising push to cross its goal.
  • Friday, June 12: FISA Section 702 statutory expiration. FISA Court certifications keep collection running until April 2027 regardless. The "expired" headline is the lever. What comes next is the policy fight.
  • Connecticut SB 4 implementation: The deletion portal needs to be built. The 35,000-consumer threshold takes effect July 1. Watch for the CT AG's first implementation guidance, and for the first data-broker registration enforcement actions.
  • Maryland HB 895, 116 days to October 1: Watch for grocery chain announcements about loyalty program changes, electronic shelf label rollouts, and "personalized" digital coupon experiments that test the boundaries of the new law.
  • FROST at DIMVA (July 2026): The Graz team will present FROST at the conference. Watch for whether any browser vendor uses the conference as a deadline to change their "working as designed" position. Don't bet on it.
  • Meta's April 6 facial-recognition response: The deadline has passed. Watch for the Senate's next move: a contempt letter, a hearing, or quiet acceptance of Meta's silence.

References

  1. CBS News: Senate fails to extend FISA surveillance program as deadline nears (June 5–6, 2026)
  2. Roll Call: FISA reauthorization stalls in early-morning Senate vote (June 5, 2026)
  3. EFF: Pulte Appointment Underscores Need to Reform Section 702 Spying (June 3, 2026)
  4. Lekander, A. "New FROST attack leverages SSD side-channel to reveal browsing activity." CyberInsider, May 29, 2026.
  5. Liu, J. "Researchers say they can spy on your browsing by measuring SSD activity through a browser API." Tom's Hardware, May 28, 2026.
  6. Help Net Security: Websites can spy on user activity by analyzing SSD behavior (May 29, 2026)
  7. Williams, A. "Websites are using this FROST-y new technique to spy on users by snooping on their SSD activity." TechRadar, May 28, 2026.
  8. Citizen Lab: Uncovering Webloc: An Analysis of Penlink's Ad-based Geolocation Surveillance Tech, Report No. 191 (April 9, 2026)
  9. The Hacker News: Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data (April 2026)
  10. Sen. Ron Wyden: Wyden, Espaillat and 70 Democrats Call for Investigation of ICE, DHS Warrantless Purchases of Americans' Location Data (March 2026)
  11. NPR: A New Study Shows How Ad-based Technology Is Used for Surveillance (April 26, 2026)
  12. State of Surveillance: Maryland's Grocery Pricing Ban Takes Effect October 1: What Changes for Shoppers (June 6, 2026)
  13. NPR: How DOGE improperly accessed and shared Social Security data (January 23, 2026)
  14. Washington Post: DOGE member took Social Security data on a thumb drive, whistleblower alleges (March 10, 2026)
  15. NPR: Government investigating new claims that DOGE misused Social Security data (March 11, 2026)
  16. FTC: Credit Freezes and Fraud Alerts
  17. IRS: Get an Identity Protection PIN (IP PIN)
  18. State of Surveillance: 2026 Mid-Year Surveillance State: Five Threats That Defined the First Half (June 7, 2026)
  19. State of Surveillance: Meta's AI Chatbot Let Anyone Take Over Any Instagram Account. 20,225 Were Hijacked. (June 6, 2026)
  20. EFF: We're Fighting Mass Surveillance Tech and Winning (June 2, 2026)