A decades-old surveillance practice is facing renewed scrutiny as lawmakers question what happens behind closed doors when investigators hack devices.
Democratic Senator Ron Wyden has called on the U.S. Government Accountability Office (GAO) to examine how federal law enforcement agencies use hacking tools and spyware in investigations involving Americans. In his view, the public lacks sufficient open information about the scale, frequency, and legal basis of such operations.
In a letter sent on Friday, Wyden requested a comprehensive review of the practices of the FBI, the Drug Enforcement Administration, Homeland Security Investigations within ICE, and the U.S. Secret Service. The audit is expected to cover the use of software for device hacking and covert surveillance in criminal cases.
Wyden demands transparency on hacking operations
According to the senator, U.S. law enforcement agencies have used such technologies for more than 20 years. At the same time, public information about the scope of these operations, how regularly they are conducted, and safeguards against potential abuse remains limited.
There is little public information regarding the scale, frequency, or operational safeguards surrounding their use.
– Ron Wyden
Wyden noted that the U.S. government regularly publishes statistics on wiretaps and the use of pen registers – tools used to record call data. However, there are no annual reports on federal hacking operations. The senator is asking the GAO to prepare an unclassified report with the findings of its review and recommendations.
What the U.S. Government Accountability Office should examine
Among the audit’s key issues are the legality of using digital hacking tools and the existence of internal controls within law enforcement agencies. Wyden asks the GAO to determine whether agency employees may have used such technologies without proper authorization or for personal purposes.
The review should also assess technical safeguards and oversight mechanisms intended to prevent improper access to surveillance tools. Separately, the GAO is asked to examine how federal agencies:
- procure hacking and spyware tools;
- store the software and access to it;
- protect such tools from leaks or theft;
- report discovered digital vulnerabilities to the government program.
The final point concerns the process that determines when the U.S. government must disclose information about identified flaws to software developers so they can address security risks.
Focus on warrants and risks to uninvolved people
In the letter, Wyden also raised the issue of judicial oversight. The GAO is expected to determine how thoroughly law enforcement agencies explain the possible consequences of using spyware to judges when seeking warrants.
In particular, this concerns risks to people who are not targets of an investigation. Hacking tools may gain access not only to a suspect’s data but also to information belonging to other users or devices connected to the target individual.
The Peter Williams case and the risk of hacking technology leaks
As an example of the consequences of weak control over such tools, the senator cited the case of Peter Williams, a former executive at defense contractor L3Harris. He was accused of stealing and selling advanced hacking tools to a Russian intermediary.
According to Wyden, those tools were later used by Russian spies against Ukraine, as well as by Chinese cybercriminals who targeted cryptocurrency holders. In the senator’s view, the case demonstrates the dangers of improperly storing and securing technologies intended for government investigations.
One of the FBI’s first uses of spyware
One of the earliest documented cases of the FBI using spyware occurred in 1999. During an investigation into illegal gambling and loan-sharking, agents discovered that Philadelphia mobster Nicodemo S. Scarfo had encrypted a file on his computer using Pretty Good Privacy (PGP).
Investigators believed the encrypted file contained important evidence. To obtain the password, the FBI installed a primitive malicious program on Scarfo’s computer that recorded keystrokes. This allowed agents to decrypt the data.
Ron Wyden’s request to the GAO is intended to show how the rules governing federal agencies’ use of hacking tools have changed over more than two decades and whether current oversight mechanisms are sufficient to protect citizens’ rights.
Click Here For The Original Source.
