Andrew Guthrie Ferguson on Surveillance, Data, and the Erosion of Privacy

Andrew Guthrie Ferguson with Sean Carroll

Show: Sean Carroll's Mindscape

Watch → · Listen →

Cleaned and reformatted from published transcript or auto-generated captions — punctuation added, filler removed, restructured for readability. Not verbatim. For exact quotes, refer to the original.

Contents

    The Anthropic–Defense Department dispute and self-surveillance

    Sean Carroll

    The week I'm recording this, one of the many things that appeared in the news was a conflict between the US government and Anthropic, the AI company. The Defense Department wanted to use Anthropic's AI in some of their applications, and Anthropic wanted certain protections that it wouldn't be used for purposes they didn't approve of. The Defense Department did not go along, so the whole thing fell apart.

    Most of the attention went to the fact that Anthropic didn't want its AIs used in autonomous weaponised drones — putting a killing machine out there under the control of the AI. That's an important debate. But there was another thing they cared about quite a bit: the use of their AI for surveillance. The AI is not out there with a video camera collecting the data, but as the CEO, Dario Amodei, pointed out, once you have AI, the way you can use surveillance data changes dramatically.

    It's easy to imagine so much surveillance data that it almost can't be misused, because it's just too hard to search through without a very specific target — until you have AI. Now you can search through this huge data set and effectively surveil everyone in the United States without their knowledge. Today's podcast is about a closely related topic: what our guest, Andrew Guthrie Ferguson, calls self-surveillance, and how it shows up in courts and police investigations. His new book is called Your Data Will Be Used Against You.

    These days we have not only smartphones, but smart TVs, smart dishwashers, smart watches, smart cars, and they're all sending data somewhere — not to mention devices you literally talk to, like your Alexa, or devices that literally surveil you, like cameras inside and outside your house. That data goes somewhere. You might think it's kind of like wiretapping — we're wiretapping ourselves all the time — and that there are legal safeguards to prevent misuse. Turns out, not so much. There are some, but the pace of legal progress is much slower than the pace of technological progress. Andrew Guthrie Ferguson, welcome to the Mindscape podcast.

    Andrew Guthrie Ferguson

    Thank you so much for having me.

    The classroom parable: the trap of self-surveillance

    Sean Carroll

    Your book has the lovely title Your Data Will Be Used Against You — no beating around the bush, no ambiguity. It's just an imperative. You start the book with a gripping little anecdote about how you teach your classes at the law school. Tell us that story.

    Andrew Guthrie Ferguson

    I begin my seminar class at GW Law School with a question for these wonderfully young, eager, and digitally conversant citizens. I ask if any of them have travelled over the last break, and almost all of them have travelled somewhere. Then I ask if they used a map to get there, and I get puzzled looks — maps, like those paper things our grandparents used. Then I ask how many asked human beings for directions, and no one wants to raise their hands. Then I ask how many used those magic devices in their pockets, or the GPS in their car, and everyone raises their hands.

    I say, 'How many of you know that that data is available for police and prosecutors and can be used against you in a court of law?' Some hands raise, all sheepish looks to the side. I say, 'Will any of you change that choice?' And they say, 'No.' That's what the book is about — the trap of self-surveillance. We've built our lives around these digital conveniences, whether Amazon Echoes in our homes, or any modern car, which is basically a surveillance device tracking you, or smartwatches that record your heartbeats, or smartphones. Our digital lives reveal who we are and what we do. Every time you purchase a smart device, you're really purchasing a surveillance device. The book wrestles with whether these are wise choices, and whether we could have all that digital convenience but also some protections so the data might not be used against us.

    Sean Carroll

    Do you yourself use Google Maps?

    Andrew Guthrie Ferguson

    Of course. I can't get to my kids' soccer games without it. I'm old enough to have had actual maps in my older cars, and those little TripTiks you used to get from AAA, where they'd print out maps you could turn page by page on a long trip. I know that world, but without Google Maps I'd be lost every weekend.

    Sean Carroll

    That by itself is an illuminating anecdote. You recognise, as well as anybody, the dangers of our self-surveillance regime, but we do it anyway because it's so convenient — so we just have to figure out how to allow for that convenience.

    Andrew Guthrie Ferguson

    The book is a meditation, not a condemnation of why we choose these things. I understand why people put Ring doorbell cameras outside their front door, or a camera in their home to watch their cat, or want to know about their sleep patterns. But what we haven't wrestled with as a society is that each one of those devices is watching us — and we think we're protected from the government getting access. If you walked out of your house with a 'No Kings' protest sign, your doorbell camera probably recorded it. If you drove to the protest in a car that records where you're going — which it does, because that's how the map system works — someone can figure that out.

    In a world where we've seen the weaponisation of political prosecutions, and where what counts as a crime might change — whether you're talking about seeking an abortion or kids who want gender-affirming care — the risk of who could be criminalised has expanded. At the same time, people do really bad things, and we want police to have access to some of that data to solve what would otherwise be an unsolvable crime, because the individual left a digital trail behind them. Coming up with that balance is what this book is trying to do.

    The analog law behind a digital world

    Sean Carroll

    You're a law professor, so I'm interested in both the technological and the legal sides. Maybe it'd help to ground us: what was the landscape like 50 years ago? How far back do you have to go before all this self-surveillance? Data was collected on us in some sense — there was eyewitness testimony — and there were some legal safeguards.

    Andrew Guthrie Ferguson

    The scale, scope, and aggregation of data has radically transformed the power police have, and yet most of our law still exists in an analog world. When I teach criminal procedure, I have to explain to my students what microfiche is, because there are still controlling cases involving police going to a bank and getting microfiche records. The seminal Fourth Amendment case that defines whether we have a reasonable expectation of privacy involves a payphone that you had to put a nickel in, and FBI agents who wanted to record it had to bring a real tape recorder, put it on top of the payphone, press record, wait, and come back and press stop. I have to explain all that to 23-year-olds who live in a world where there are microphones in everything and who've never seen a payphone.

    The law that governs this hasn't updated to the new world. Part of what the book does is show how we've built this self-surveillance trap without building the similar architecture of constitutional rights under the Fourth Amendment, or even statutory rights — Congress could change this balance of power, but hasn't. As a law professor, I see the technology moving at an advanced pace, with AI going even faster than we could have imagined, and I see the law that literally doesn't change, casebook after casebook, because I've been teaching it the same way for 16 years. That disconnect is a reason to raise the issue with the public.

    The Fourth Amendment and the reasonable expectation of privacy

    Sean Carroll

    You dropped a couple of crucial ideas. One is the Fourth Amendment — my favourite amendment, actually, of the first ten. Tell us what that is.

    Andrew Guthrie Ferguson

    In the Bill of Rights, the Fourth Amendment says the government is not allowed to search persons, papers, homes, or effects. There's a requirement that a search not be unreasonable, and nowadays a requirement of a judicial warrant to get access to some of those protected things. The payphone case I mentioned is called Katz v. United States, and it basically said we could interpret the Fourth Amendment in the modern age to ask whether someone has a reasonable expectation of privacy. That term doesn't really mean what you think it means — you have to go to law school to understand it — but it says whether something is a 'search' for Fourth Amendment purposes turns on whether it violates an expectation of privacy.

    Easy example: your home is a place of privacy. What you do there generally can't be seen by law enforcement, and it's accepted that police need a judicial warrant to go into your home. The hard question is: what if you have cameras in your home that don't just stay there but also go to a third-party cloud provider like Google or Amazon? What if you have microphones in your home — Echo devices — going to Amazon? If the police don't go to your home but instead go to the third party you asked to hold this data, do they need a warrant? It's an open question, because it's hard to know whether you have an expectation of privacy in the data that third party holds.

    Sean Carroll

    That was wonderful, thank you. The other idea you dropped was controlling cases, and this fascinates me — if the physics thing hadn't worked out, law school was definitely one of the things I might have done.

    Andrew Guthrie Ferguson

    It's not too late.

    Sean Carroll

    I like to say that to other people, so I should listen to it myself. The Fourth Amendment, like all parts of the Constitution, is hugely important but a little vague — it doesn't spell out every nook and cranny of possibility. Not even legislation does, and we expect court cases to tell us what the Constitution and the laws mean. Is that more or less right?

    Andrew Guthrie Ferguson

    Yes, and it's great to think about in the world of technology. At the time of the founding, the Founding Fathers did not have smartphones. If you think about the information in your smartphone, it's very private — it holds all your photographs, your emails, your texts, maybe your financial information, and the choices you've made about what to read, whether the New York Times or Fox News app. A question came before the US Supreme Court about whether police need a warrant to go into your phone to find evidence. In that case, detectives thought there was incriminating evidence in the man's phone, went in without a warrant, and it went up to the Supreme Court to decide what the Fourth Amendment means in an era of smartphones.

    The court said that because of the private information in our phones, police need a judicial warrant to go in. In these cases interpreting new technologies against old law, the court usually has a paragraph pleading, 'Please, Congress, please regulate this. You are far better than we are. We're just interpreting a document drafted in 1791.' But Congress, for the most part, has not acted, so we have the Supreme Court interpreting things — maybe rightly in that situation, because the information in your phone is probably more private than the things in your house. But it was an open question, and could easily have gone the other way based on the arguments of those nine justices.

    Weak warrants and the data police can always get

    Sean Carroll

    This is where it's fun to learn how the legal system works. If you ask, 'Do I want police to have access to my cell phone or emails?' I'll say no. But if you ask, 'What about the emails of a serial killer or a terrorist?' a lot of people say yes. There has to be a procedure written down as clearly as possible for distinguishing between the two.

    Andrew Guthrie Ferguson

    The book focuses on exactly that tension. It's filled with examples where police use our data against us in ways many people would be fine with — you found the murderer, you found the person who shot someone. I'm not against that; the warrant requirement makes sense. But there are two things to recognise. First, judicial warrants are kind of weak sauce. It's actually very easy to get one. The standard is probable cause, which is decidedly less than 51%, which would be a preponderance of the evidence. You can be less right than 51% — probably more like the 30s — and still get a warrant. All you need is a criminal predicate, which doesn't have to be much. So if protesting ICE becomes a crime because you're disrupting federal authorities, then your data is available to the government, because they have the predicate crime.

    The thing that struck me most in writing this book is that there is no data so private police cannot obtain it with a warrant. Your smart bed, your digital diary, your period app that tracks your menstrual cycle — with a warrant, police can get anything you've created. I'm not sure that's really the balance we want.

    Sean Carroll

    So when you get a judicial warrant, maybe there are things you'd otherwise have thought private that the police should get — but maybe there are also things the police should really never get.

    Andrew Guthrie Ferguson

    Right, and my favourite story about this is in the book. We can all agree that a smart pacemaker living in your heart, keeping track of your heartbeat, is a wonderful innovation that saves lives — exactly what we'd want to encourage. There's a person in the book who has one of these pacemakers, which reveals his heartbeat to him so he can stay alive, and also sends data to his doctor. Detectives went to his doctor's office, got the readout of his heartbeat, and used it against him in court. Why? Because he was also committing insurance fraud — an arson scheme where he burned down his house and asked for insurance money. The detectives wanted to disprove his story by showing that his heartbeat didn't line up with his account of running around in the fire.

    You have a crime, and yet we might pause and say maybe we want to carve out things so that our smart heartbeat — which we otherwise couldn't live without — might not become evidence against us. Or, even if we're willing to change that balance, maybe we want a higher standard warrant. We haven't had that debate, because we're building these devices into our lives and we're pretty dependent on the digital trails, without building equivalent scaffolding of protections.

    Every device is a surveillance device

    Sean Carroll

    Maybe it's worth mentioning some of the other technologies broadcasting information about us. It's not just phones and pacemakers — cars are doing things, appliances in our homes, and our security cameras are spying on us as well as the bad guys.

    Andrew Guthrie Ferguson

    Of course. When people buy the Ring doorbell camera for a sense of security, they have to recognise that 99.9% of the time you're just recording yourself and your neighbours. The odds that someone steals your package are pretty slim over the arc of your life. So you're creating all of this footage that could be used against you. Sometimes you think that's fine, because if something bad happened you'd want police to access it. But you might also say, 'I don't like living with the vulnerability that I get a knock on the door and the police say, "We have a warrant, we'd like access to see who's been coming into your house."' If we learned tomorrow that the government was going to take control of your camera and have access to who's coming in and out, we'd all say, 'That feels a little dystopian, we don't want that.' And yet we're building that ourselves, unthinkingly. Once you build it, they will come.

    Sean Carroll

    There's a meme that goes around the internet of lawyers giving free advice: never talk to the cops, just shut up, don't volunteer anything. It seems that, whether we like it or not, we're kind of always talking to the cops — broadcasting information about ourselves.

    Andrew Guthrie Ferguson

    We're pretty vulnerable. My book isn't so much that we shouldn't embrace the digital innovations that make our lives better. It's that we should also agree on limits — certain kinds of information maybe shouldn't make its way into a criminal case. It's true there will be costs; there will be cases you can't bring, or you'll just have to bring them the way you did for the last couple of centuries. The Founding Fathers didn't have cameras recording in their houses, and there were probably cases that couldn't be brought because the evidence didn't exist. We lived with that. We should embrace the benefits of this technology but put some limits on how it can be used against us.

    What's interesting is that, depending on who's in charge, we have different senses of this. A couple of years ago, Second Amendment stalwarts worried that a democratic government would come with a list of gun owners and kick down their doors. They didn't even want a database of who owns a gun and where. Nowadays, with automated licence plate readers, you put one outside a gun show, a gun range, or where you buy ammunition, and you don't need a list — you can infer who has a gun by who's going to the range. People who'd protect the Second Amendment could realise, 'Wait, I too am exposed.' In fact, Donald Trump's data was used against him, and he was kind of mad about it. He was very angry that his texts were being used. There's a bipartisan recognition that the people in power might misuse this power, so it might benefit everyone to come up with guardrails about who gets access and why.

    Data brokers and how much is actually collected

    Sean Carroll

    How much do you know about how much of the data that could in principle be collected is actually being collected and stored? People always argue about why the internet starts showing them adverts for things they only thought about but never searched for. They worry their phones or their Alexa are listening in. Do you know about the veracity of those ideas?

    Andrew Guthrie Ferguson

    There is some truth to it. Take your phone. Most people have a bunch of apps, and you don't realise that the reason you got that flashlight app for free is that the free part was your data. They're selling your identity — not your name and address, but your identity as your phone — to other companies, in a whole network of data brokers. One of those 'I agree' buttons you clicked gave away the advertising part of your phone, so it knows where you're going. That's tracked not only to sell you things — there's even a headline today that DHS is using that same advertising data for immigration enforcement, because it's a tracking device on your phone, and with enough information you can identify people's movements and eventually who they are.

    We're stumbling into a world where our movements, purchases, and likes are all tracked — not just because on social media you literally press 'like', but when you pressed it you were telling a computer that you like this, and they're recording it to sell you things. Almost everything we do in a digital world is tracked, usually for commercial gain, but with a quick subpoena or warrant it can be turned into evidence. If you're Googling 'how do I obtain an abortion in Texas', there might be people who want to sell you pregnancy-related things — but there might also be an attorney general curious about who was googling this. Everything we do in the digital space is open, because we don't have countervailing protections to close some of it off.

    The shift to a collect-everything default

    Sean Carroll

    How much are the police actually using this data? Have they become sophisticated at it, or are they not yet clued in?

    Andrew Guthrie Ferguson

    They are sophisticated, but I think we're seeing a shift. In the last couple of years police would use data to prosecute the cases we kind of want them to prosecute — a cold case with no eyewitnesses where someone left their cell phone on at the scene, or a car leaving the scene you could track by licence plate. Because those involved victims and real social harm, we weren't asking too many hard questions about whether the data could be misused. In the last couple of months we've seen a more politicised view of prosecution, and we have to realise that who could be targeted has changed. Jim Comey, a former FBI director, a career prosecutor, about as straight an arrow as anyone could imagine, is currently being charged with his own texts and data used against him, because he's now in the sights of an arguably political prosecution. We saw wise discretion in the past — maybe we shouldn't use this data, even though it was available — and now prosecutors and police are more comfortable with it. It gets cheaper and easier, and the subpoenas for certain data sets are growing exponentially because police think, 'I can find out who was at the scene with a quick request to Google — I'm definitely doing that.'

    Sean Carroll

    On the other side, do a lot of people have the impression, 'As long as I'm innocent, I'm okay,' or 'As long as I'm not the target of a political prosecution'?

    Andrew Guthrie Ferguson

    I think that's the reason we're at the place we're at, and you have to talk about the privilege it comes from. If we talk to poor communities or communities of colour, who've seen the surveillance cameras and police presence in their neighbourhoods, they might say, 'We've been seeing this for a long time — what are you talking about?' The aperture of surveillance has expanded to a more privileged class. People with 'No Kings' signs didn't realise they could get caught up in a criminal conspiracy charge for what they thought was First Amendment-protected activity. As we criminalise things that weren't criminalised before, like access to medical services, who is now at risk as an accomplice — say, part of a conspiracy to help their daughter get medical services in another state — expands.

    That's a terrible thing and a good thing. Terrible because the risk is bad; good because people who could once have said 'I have nothing to hide' might now see there's no protection but the norms or goodwill of good prosecution. That might not be the world we want to live in. We might want a bit more distrust and concern about how that data could be misused.

    Sean Carroll

    I get the impression — you already alluded to it — that how suspicious people are of the government depends on who's in power right now. My feeling is that we used to have a consensus that the government should be able to do certain things, but also that there should be checks and balances — and maybe on both sides that consensus is eroding, and we want the people on our side to be given more and more power to do what they want.

    Andrew Guthrie Ferguson

    That's a danger. The fact that there aren't people pushing back on this overreach of government power is revealing in its own way. What's also happened is that the default has reversed. It used to be that, because we didn't have the technology, you'd go about your life and if police suspected you they had to spend a lot of time and effort targeting you. Now, with cameras on the streets and automatic licence plate readers catching every car, we have all that information, so it's trivially easy to look someone up. The default is that we've collected all the data on the off chance we might need it, as opposed to collecting none and going to find something when we need it. This ubiquitous, cheap surveillance technology has changed the defaults without changing the laws or rules, and that imbalance is why we should have a new conversation about whether we're okay with it.

    Real-time crime centres and AI at scale

    Sean Carroll

    I saw an interview with Dario Amodei where he made the point that, given all the data you imagine collecting, there's in some sense too much of it — all the cameras, all the recordings — but AI gives you a way of filtering and sorting through it. So it's a combination of all the data being collected and the way it can be used against a whole bunch of people.

    Andrew Guthrie Ferguson

    I thought it was interesting that the Fourth Amendment made an appearance in this debate about Anthropic and the Pentagon and mass surveillance. What was telling was the acknowledgement that AI is a game-changer in the ability to use what is otherwise an overload of information. Maybe some of our protection had just been that we weren't at the technological level where we could use this overflow. The comment about why he didn't want to give the military access to mass surveillance should probably also be applied to AI use among local law enforcement, but we haven't had that debate.

    To make it concrete: picture a city that has adopted a real-time crime centre — a centralised command centre with lots of video screens, cameras recording on the street, connected to police body cameras, car cameras, drone cameras, even your Ring doorbell camera, and commercial cameras, all fused together. From the command centre a police analyst or commander can watch the streets and click from camera to camera, giving a full visual of a city. But the superpower is that you can run AI on all those camera feeds and identify every object — every car, truck, van, bike, every man, woman, child, dog, foreground and background. An open door, a window that's ajar. Everything that can be seen can be identified, separated, and tracked. If someone is wearing a blue sweater as they walk down the street, you can search for all blue sweaters in the city, superimposed so you see them all at once in different locations. If the bank robber wore a blue sweater, you can find the blue sweater near the bank and then track it through the city, all by object recognition.

    That kind of time-machine power — going back in time — has never existed in the history of the world, and we now have it. It's unregulated. There's no federal law on it. I've written a law review article about the Fourth Amendment on it, but that's a law review article; there's no real law. And yet it fundamentally changes police power and citizen power in America in really hard ways. That's the power of AI. That is mass surveillance at scale with real consequences.

    Sean Carroll

    Apparently Anthropic said no, but not everyone says no. There's a capitalist aspect to this too — people want to make money off these things, and often collecting data and giving it to the government is going to make them money.

    Andrew Guthrie Ferguson

    Almost everything we're talking about is not a free device — and if it's free, you're the product; your data is paying for it. We not only have companies vying for this, but an interesting new world where, because the technology is sophisticated, the technology companies are becoming the platform for policing. Your ordinary police chief isn't a data scientist running the object recognition AI; they're dependent on a private company, which might have competing interests. If you're a public company like Axon, you're beholden to your shareholders to maximise profit — that's literally what you're supposed to do. A private company trying to sell products elsewhere has different interests from the public. We've never outsourced public safety to private companies the way we're doing now, and it raises really difficult questions about whether we should.

    Sean Carroll

    That scenario you painted with the clearinghouse tracking blue sweaters — was that hypothetical, or are cities building those things?

    Andrew Guthrie Ferguson

    Oh, we have them — in 300 different jurisdictions in America. Many big cities have real-time crime centres, and I personally believe it will be the future of policing, because it's really helpful for police. They get a 911 call, click on the nearest camera, maybe send a drone for operational awareness, and have a data set of past crimes or who lives in the area. They can go camera to camera to give the responding officer, before they've reached the scene, a full sense of what's about to happen. That's a great tactical advantage and great for collecting evidence, because all the people who might have scattered before police arrived are captured on camera, and every licence plate is recorded so you can figure out who was a witness. It's an incredible superpower for policing that isn't going away.

    At the same time, we haven't built in rules for what happens if there's impeaching or exculpatory information in that database — what do you do with that, and how does it intersect with the actual criminal prosecution months later? Those are open questions where the technology has got ahead of a pretty traditional, old-school criminal trial.

    Predictive policing and its record of failure

    Sean Carroll

    Are police edging into anticipatory policing — getting the feeling that a crime is about to be committed here?

    Andrew Guthrie Ferguson

    We've had an interesting experience with predictive policing, which sounds more like Minority Report than what it really was. There are two parts. Place-based predictive policing says certain areas are at higher risk, so maybe you send a police car there in anticipation. Some of it sounds like science fiction, but you can imagine Friday night at 1 a.m. when the bars let out — will there be an uptick of robberies? Probably, because there's a bunch of drunk people with money leaving a bar. In certain parking lots you might have an uptick of car thefts, because there's no police around, bad lighting, and an easy escape route. There's some logic to it, but a lot is hard to do, and most of the early iterations proved unworkable or ineffective and were shut down.

    There's also person-based predictive policing — the idea that we can look at your past criminal record and your contacts with police and predict you might be more at risk of being involved in a crime. Those experiments also largely failed. We saw them in Chicago and Los Angeles, and they didn't work in theory or practice. But that doesn't mean that with this new world of more data and more faith in AI we won't see it again. I imagine we'll start seeing some version of predictive policing with AI in the next couple of years — not because it will work, but because it sounds good, and people always want to get ahead of the criminal risk. If you can say you bought technology that gives you that advantage, people might want to buy it whether or not it works.

    Facial recognition and the eyewitness parallel

    Sean Carroll

    It gives the impression of being techy and sciency. I wonder if, in a courtroom, the fact that evidence comes from hard data makes people a little less sceptical of it than they would be of eyewitness testimony — maybe they shouldn't be, but it certainly can make mistakes.

    Andrew Guthrie Ferguson

    That's true. Facial recognition is a great parallel to eyewitness testimony. Eyewitness testimony is responsible for many wrongful convictions — people are bad at making identifications when they're scared, in traumatic situations, and cross-racial identifications are especially bad. But facial recognition also has its own errors. We've seen at least nine false arrests of people who were absolutely innocent, but facial recognition said they were guilty, and they were literally arrested, dragged away from their families, and put in jail before we figured out the error.

    Imagine you're on the jury and someone says an algorithm suggested a 95% match, and you don't know what that means — it's pretty convincing. The real danger is that the detectives are not data scientists. They don't know how facial recognition was created or what a 95% match means, and it's kind of unfair to expect them to. Yet they get the printout saying, 'This is your suspect, the computer thinks it's a match, go.' What are they supposed to do with that? We haven't created a world with a double or triple check on it, or a moment afterwards to expose a wrongful conviction — except when the defence lawyer gets evidence that this person has an alibi. Many times the fact that facial recognition was used doesn't even have to be turned over, so the defence lawyer doesn't even know it was the reason detectives showed up and dragged someone away.

    Sean Carroll

    Do I remember correctly from your book that not only does the fact that it came from facial recognition not need to be turned over, but that if the software identified other plausible suspects, that also does not need to be shared with the defence?

    Andrew Guthrie Ferguson

    Exactly. Facial recognition takes a face print — think of a fingerprint, but a face print — breaking down the distances between your eyes, nose, mouth, lips, and ears, and matching them up. When you query the data set with a probe photo of your suspect, by default it gives you many suspects, not one. It'll give you between six and a hundred, depending on how you set up the program. If you're a detective and you ask for the top ten, you literally have in your hands presumably nine innocent people and one the computer thinks is the better suspect — and the other nine are never turned over to the defence. The investigation proceeds as if facial recognition got the person right, even though it thought there were nine other people with different levels of certainty. The top suspect might be 95, below them 93, 92, 91 — and it could be that some of the lesser certainties are actually more likely the person, but the defence lawyer would never get access to that.

    Sean Carroll

    Do defence lawyers typically have access to the raw data? Could they do it themselves?

    Andrew Guthrie Ferguson

    No. They won't have access to the same data set to do the facial recognition. They might see the probe photo that went into it, but it's usually a police database or a Department of Motor Vehicles database in some states.

    What can be done: judges, legislators, and communities

    Sean Carroll

    That leads us to how we could do better. It sounds like we have to think about the judicial level, the legislative level, the police level, even the personal level. Where should we start? What should the strategy be?

    Andrew Guthrie Ferguson

    The book divides the solutions into different chapters. One is essentially written for judges, about how we could update the Fourth Amendment to match this digital age and respond to our expectations of privacy. Another involves the legislative response — building up the idea that we require a warrant. We have something we've lived with since the late 1960s called a wiretap. The federal government can put a microphone in your bedroom or kitchen and listen to you and your family — usually if you're in the mob or they think you're a terrorist. To do that very invasive thing, they have to go to a judge, explain at a higher standard of probable cause why there aren't other ways to get the information, and then go back to the judge to explain what they got and minimise the other conversations, say if your kids are in there. We've lived with this since the late '60s, and it's about as invasive as you can imagine. The book proposes something akin to the wiretap act for these other digital technologies — it raises the bar of how police can get the data. They can still get it. People aren't complaining about the wiretap act because the protective processes are in place.

    Then there's a chapter on what communities can do. It's unfair to say what individuals can do, because you and I can't negotiate with Amazon or the FBI, but communities can push back and get legislators to respond. First is education about the problem. And we can make some choices — maybe you don't need the cat cam; cats have survived many years without you watching them. The point of the book isn't to critique people for buying this technology; it's to interrogate whether the protections on that data are as secure as we think. They're not.

    Sean Carroll

    The wiretapping analogy is a great one. We're now all wiretapping ourselves, and there isn't even the same protection as for real wiretaps. All my knowledge about the wiretap comes from watching The Wire, and I'm pretty sure most of the time the detectives just sweet-talk a judge into a warrant — it's not very systematic.

    Andrew Guthrie Ferguson

    It's actually relatively rare for its power. You'd imagine there are lots of people you might suspect of criminal activity, and it would be great evidence to listen to their living-room conversations, but we don't see it happen that often, partly because you have to show there's no other way to obtain it and you have to report back to the judge afterwards. So it gets saved for the most important, long-standing investigations. That might be a compromise: if you really think someone's doing something horrible and you want access to their Ring doorbell camera, convince a judge to a higher standard, explain why there's no other way, and recognise that all the other footage we won't use — we're only focused on the crime we can identify and explain. Maybe society is okay with that. We don't have that now. The default is that because you recorded it, uploaded it to a cloud, and checked 'I agree' that you can share with law enforcement, they can just get it — they might not even need a warrant.

    How long data lives, and companies' incentives

    Sean Carroll

    How much data is kept over time? The difference between this self-surveillance and traditional wiretapping is that the wiretap starts at a moment, whereas self-surveillance is ongoing. Does Amazon have records of what people are asking Alexa for years into the past?

    Andrew Guthrie Ferguson

    It all depends — it's technology-dependent, company-dependent, and depends on how they're monetising it and how aware they are of privacy criticism. Some apps on your phone that you forgot you have have been tracking you since you installed them, selling and reselling the data without your knowing, and it'll keep going because you got a new phone and downloaded the same app without thinking. Some data gets erased over time, because it actually costs money to store data — it's not in a company's interest to keep data they don't need.

    Ring changed from storing everything on the cloud to storing things in the actual camera, which limits how much it can hold. They did that because people complained it was too easy for law enforcement to get access — so now officers have to go with a warrant to the homeowner, and the company is out of it. That's a privacy-protective step. Apple has taken privacy-protective steps too: if you use face identification on your Apple phone, the face print is stored on your phone, not the cloud. Companies can do some of that to protect you. But there's sometimes a race to the bottom, where companies give you something that seems too good to be true — free access — and you're not paying attention to the fact that the free comes at the cost of your data.

    Sean Carroll

    Wasn't it Ring who had that Super Bowl commercial that backfired?

    Andrew Guthrie Ferguson

    Yes. Ring advertised what was supposed to be a heartwarming idea: that you could find your lost puppy in the neighbourhood by activating all the cameras at once, through their partnership with Flock. People saw that and said, 'But that means you can do this for anything — you've just taken over my camera to find people who are protesting, or the labourers working in our neighbourhood, or anyone.' That feels invasive. The companies are exploiting the lack of law. There's nothing unconstitutional or illegal, because there are no rules — they just said, 'We have the technology, we can do this, and we'll build it.' The public reaction made them realise there really is a privacy fear. My suggestion to everyone is that every time you see law enforcement doing something that seems a little privacy-invasive, remember they can probably do it to you as well.

    Sean Carroll

    And maybe we should be pushing to change that status quo. Is there an issue with the fact that Silicon Valley developers have a certain mindset that might not be the average person's? Not just that they had the capacity to do the thing with the Ring cameras, but that they thought everyone would be in favour of it and were surprised by the backlash.

    Andrew Guthrie Ferguson

    That might be part of the concern. There are people who embrace this digital life — they wear the Aura ring on their smartwatch, live the quantified life with a smart water bottle that tells them how much water they've drunk. People give all their data to their agentic AI to plan their kids' birthday parties, and there's a trust in that. What they don't realise is that all that data now exists in a world also accessible to law enforcement. Say the federal government is mad at a certain AI company because its CEO stood up to them publicly — guess whose data is now exposed. Even the most powerful billionaires, even sitting senators, are exposed by their data. If you're a senator, do you want all your Google searches available to the FBI director? Probably not — it's probably embarrassing. If you're a Supreme Court justice, you probably don't want all that information out there. People live in protective bubbles because they think privilege will protect them, but it's pretty easy to get on the wrong side of power and have all that data weaponised against you.

    Under the radar, and the dystopian worst case

    Sean Carroll

    What's your feeling for how seriously this issue is being taken, whether in legislatures or advocacy groups? Are people raising the alarm, or is it still slipping under the radar?

    Andrew Guthrie Ferguson

    It's still under the radar, mostly because people haven't read my book — so please help me get people to read it. We've been sleepwalking into this moment. There are lots of distractions and issues in America today, but this ties together a lot of themes. People are starting to feel more vulnerable, to see the creeping sense that both tech companies and government powers can use all this consolidated information about us to control us. The sense of who's vulnerable is expanding, and this might be the moment for that conversation, recognising there's no one who is not vulnerable. In a couple of years the power dynamics may shift, and people who are suddenly in power may not be. Do you want all your data used against you when the power shifts? It always shifts back and forth. Hopefully the book starts that conversation now. But it'll take people seeing and feeling the fear before we get any legislative or judicial action.

    Sean Carroll

    You have a chapter near the end called the tyrant test, about whether certain technology could be helpful to a hypothetical autocrat. Maybe this is unfair, but what's the worst-case scenario? What's the truly dystopian future we could fall into if we're not careful?

    Andrew Guthrie Ferguson

    We see an image of it in China right now — hundreds of thousands of surveillance cameras with AI recognition, financial and communications information controlled through social credit scores, everything done digitally, and a centralised government that wants to use that data for social control. It can control the population by what you see, what you do, and how you act. Ironically, there are upsides — a lot less crime, fewer robberies — but a lot less freedom as well. We can see a window of what happens when we put cameras everywhere, have unrestrained access to them, and have sensors and computers monitored by the government. If access to what you purchase and how you communicate is all monitored, we don't live in the free society we think we do.

    Here's the story I always tell. Imagine tomorrow the government said, 'All American citizens have to have a wiretap in their house. They have to have a camera on their door. We're going to have a network of surveillance snitches saying what's going on in the neighbourhood. We want to know what you're reading, what you're buying, and we'll monitor your purchases.' That seems dystopian. But that's everything you've probably given Amazon alone — you have an Echo, a Ring doorbell camera, they know your Kindle reading, they know what you're purchasing, you have the Neighbors app. That's one company you've willingly paid to give all your data. To Amazon's credit, they're usually consumer-facing and good for consumers, which is why everyone uses them. And yet all that data is available to law enforcement. If you become the target — whether you're a senator or just critical of the government — all that information can be used to embarrass you or reveal who you and your family are. If you think, 'But we have a judicial warrant,' well, if there's a predicate crime of sedition because you're critiquing the government, or you're part of 'Antifa', whatever that means, it's all open. We grew up in a world where we were okay with that because we thought the companies had our back, but sometimes the interests are conflicted, because Amazon also has federal government contracts and a bottom line. As a US company they have to comply with a lawful subpoena or warrant — they can't say no. That vulnerability applies not just to Amazon, but to all the companies: Google, Facebook, any consumer data system. It's all available.

    Aiming the law, and the honest bet

    Sean Carroll

    I'm not sure if this is a well-formed distinction, but at the level of legislation you might imagine getting passed, is it more important to aim at police and criminal procedure, or at the companies collecting and offering this data to law enforcement?

    Andrew Guthrie Ferguson

    In the book I had a choice: focus on a data protection or data privacy law, or something narrower focused on controlling what police and prosecutors could use. I chose the police-and-prosecutor one — not because data privacy isn't critically important, but because we've seen Congress fail to move forward on it. There have been proposals, but I don't have faith we'll answer it now. This smaller piece might be something we could compromise on, because everyone is equally at risk there. In a perfect world, you could have all the Amazon conveniences of life and not worry that data would be used against you. I'd like to use Google Maps to get to my kids' soccer games without Google Maps being used against me. That might create a problem if I become involved in a criminal action, but that's the compromise I'd prefer — where I could benefit from smart heart devices or the Aura ring, which I don't own, and not have to worry that my blood pressure levels will suddenly be evidence against me in court.

    Sean Carroll

    We all either use or attempt to use Google Maps and Amazon. Are there obvious things we're doing badly — steps we can take to clean up our digital footprint, like removing apps on our smartphones?

    Andrew Guthrie Ferguson

    Just ask yourself: is the value-add here worth it? For me, Google Maps is definitely worth it; the Ring doorbell camera is not. But that's just me — everyone makes their own decisions, and I'm not here to criticise. I do want people to interrogate that if you put the Ring doorbell camera on, you're surveilling yourself more than anyone else. You're also surveilling the workmen in the neighbourhood, your postal carrier, your kids coming back and forth, the people you invite over. Are you okay with that? Maybe your answer is yes. But we might all be more comfortable in a world where the only way police get access to that camera is not a simple warrant, but something greater — a higher standard, because you created the data they want to invade. Then we'd have the best of both worlds. I think it's in the companies' interest too: they'd say, 'We'll sell you all the technology; for law enforcement to get it they have to meet a higher standard, but that doesn't affect us.' We'd live in a world where we benefit from consumer convenience without worrying about its double edge.

    Sean Carroll

    You've sketched both a pessimistic and an optimistic scenario for how we can make these compromises. So my last question is going to be super unfair. What's your bet? What's the likelihood we'll figure this out without tremendous abuses along the way?

    Andrew Guthrie Ferguson

    There's probably some low-hanging fruit. From the judicial side, it's pretty easy to interpret the Fourth Amendment to be a bit more protective. The Supreme Court has a case this term about a geofence warrant — whether the locational data around a crime can be obtained, because Google was tracking everyone's phone at all times, so it's easy to get access to whoever might have been near a crime. We'll see if they respond in a more 'digital is different' way, recognising the world has changed from the analog world of their older cases. Getting anything through Congress is difficult, and I haven't been terribly optimistic about that kind of progress. But we've seen movements grow. The world is waking up to the dangers of centralised law enforcement that might be weaponised for political purposes. The moment now is more promising for a consensus to do something than it was even a year ago. The danger might clarify the risks, and maybe that would lead to some movement forward.

    Sean Carroll

    The moment now is a wee bit more promising — I'm going to cling to that as our final message. Andrew Guthrie Ferguson, thanks so much for being on the Mindscape podcast.

    Andrew Guthrie Ferguson

    Thank you.