A lot more than a pen register, and less than a wiretap: what the StingRay teaches us about how Congress should approach the reform of law enforcement surveillance authorities.

   A. Real-time Cell Phone Tracking and Secrecy
   B. The StingRay and Secrecy
      1. The 1995 Digital Analyzer Magistrate Opinion
      2. 2012 StingRay Magistrate Opinion


Beginning in June 2013, the details of several National Security Agency (NSA) classified surveillance programs were revealed in a series of articles by journalists who had received documents from ex-NSA contractor Edward Snowden. (3) Among the many disclosures and subsequent releases of information by the Administration and Members of Congress was the revelation that, since 2006, the NSA has been collecting domestic call detail records and other domestic telephony metadata (4) in bulk, pursuant to a controversial interpretation of Section 215 of the USA PATRIOT Act (PATRIOT Act). (5) Section 215 is an intelligence collection authority permitting the government to compel "tangible things" from third parties that are "relevant" to an "authorized investigation" in order: (1) "to obtain foreign intelligence information not concerning a United States person"; or (2) to "protect against international terrorism or clandestine intelligence activities." (6) The public has also learned that this massive quantity of data is collected and stored in a centralized database in order to enable future searches by the NSA--that is, if and when there is a reasonable articulable suspicion that an identifier (e.g. a phone number) is associated with a particular foreign terrorist organization (7) or with terrorism. (8) The goal of the program is "to enable the government to identify communications among known and unknown terrorism suspects, particularly those located inside the United States." (9)

One major criticism of this domestic surveillance program is that the "common sense" reading of the statutory text of Section 215 does not, on its face, appear to permit collection on this scale. More specifically, critics argue that the contents of an entire massive database of records--in this case the records of nearly every domestic telephone call (10)--cannot simply be deemed relevant because some of the records in that database are actually relevant to an investigation. (11)

While the existence of this intelligence program had been kept from the general public prior to the summer 2013 Snowden disclosures and subsequent declassification of information by the Executive branch, some members of Congress knew of its existence and were privy to the statutory interpretation the government was employing to justify the bulk collection of domestic telephone records. Indeed, during a floor debate in 2011, Senator Ron Wyden warned his colleagues that "when the American people find out how their government has secretly interpreted the PATRIOT Act, they will be stunned and they will be angry." (12)

As this Article goes to print, the Executive and Legislative branches of government are finally engaging the public in a much more robust, transparent discussion about the Section 215 metadata program. Moreover, as the Administration continues declassification of Section 215-related documents, several Members of Congress are calling for reforms to the statute, some arguing for termination of the entire Section 215 bulk collection program. (13) Even President Obama has suggested that the government should no longer hold the data, although the Administration has not yet taken a position on who or what entity should warehouse the voluminous call records and other telephony business records. (14)

Meanwhile, a clearer picture of earlier cryptically worded criticisms of the program voiced by members of Congress has emerged. We now know that some members of Congress who were aware of the government's legal interpretation of Section 215 actively urged the Executive branch to engage in a more public discussion of the issue in a manner that would not harm national security. In other words, as controversial as the Section 215 program has come to be in light of the Snowden revelations, prior to those unauthorized disclosures an established process had already enabled at least some measure of congressional oversight and review. (15) That process, in turn, enabled Senators Russ Feingold, Richard Durbin, Wyden, and Mark Udall to warn the public and other members of Congress that the government was misusing its Section 215 authority, albeit in opaque and suggestive language necessitated by the classified status of the surveillance program. (16) While it is fair to argue that congressional oversight of government intelligence programs is far from ideal, we must at least acknowledge that the government's expansive interpretation and use of Section 215 was known and debated by some Members of Congress--some approving of the program, (17) some not--even if it could not be directly named or described in public until after Edward Snowden's disclosures. The efficacy of an oversight regime burdened by such strict secrecy is now the subject of justifiably intense debate.

In the context of that debate, this Article examines a very different surveillance technology--one that has been used by federal, state and local law enforcement agencies for more than two decades without invoking even the muted scrutiny Congress applied to the 215 metadata program. (18) In that time, this technology has steadily and significantly expanded the government's surveillance capabilities in a manner and to a degree to date largely unnoticed and unregulated--indeed, it has never been explicitly authorized by Congress for law enforcement use. (19) This technology, commonly called the StingRay, the most well-known brand name of a family of surveillance devices known more generically as "IMSI catchers," is used by law enforcement agencies to obtain, directly and in real time, unique device identifiers and detailed location information of cellular phones--data that it would otherwise be unable to obtain without the assistance of a wireless carrier. (20) Whether installed in a vehicle, mounted on a drone, or carried by hand, this unregulated and technologically unmediated surveillance technology can, for example, send signals through the walls of homes to locate and identify nearby cell phones without the assistance of a wireless carrier and without providing any notice to the targets of the surveillance operation. (21)

This Article describes how the StingRay's unmediated collection capabilities do not fit well into the post-9/11 (or, for that matter, pre-9/11) Pen Register and Trap and Trace statute ("Pen/Trap"), (22) the criminal surveillance authority normally used by federal law enforcement agencies to acquire certain types of non-content communications data in real-time. The lack of specific statutory authorization has not, however, served as a practical barrier to use of this technology by law enforcement agencies. Indeed, for several years prior to the passage of the PATRIOT Act, the official Department of Justice (DOJ) policy was that, since no specific statutory or Fourth Amendment prohibition forbade the practice, law enforcement could use StingRays without any form of judicial oversight. (23) After the PATRIOT Act broadened the definitional section of the Pen/Trap statute, DOJ interpreted the statute to authorize the collection of nearly all non-content information exchanged between a mobile device and a cell tower and, accordingly, advised prosecutors to obtain a Pen/Trap order when employing IMSI-catchers in an investigation. (24)

The StingRay, therefore, illustrates how the legislature's authority can be effectively short-circuited when: (1) the government stretches existing statutory definitions to accommodate a new type of collection capability or surveillance technology not contemplated by Congress; and (2) there is no established mechanism to ensure legislative notice and review that would enable Congress affirmatively to choose whether or not to regulate the government's use of new or existing surveillance methods and technologies.

Drawing from the lessons of the StingRay, this Article argues that, if statutory authorities regulating law enforcement surveillance technologies and methods are to have any hope of keeping pace with technology, some formalized mechanism must be established through which complete, reliable and timely information about new and existing government surveillance methods and technologies shall be brought to the attention of Congress. That information, among other things, must include: (1) how the government interprets existing law to permit or, conversely, not to prohibit its use of a particular collection method; and (2) how it uses such technologies in criminal investigations.

Moreover, through a discussion of how the StingRay has evaded formal congressional oversight, this Article identifies several specific characteristics of any new or existing surveillance technologies or methods that should guide Congress in assessing the need for new regulation, as well as periodic assessment of any potential need to update existing statutory authorities to accommodate technological change and innovation. Finally, under the theory that Congress cannot begin to address the policy challenges posed by new surveillance technologies in the absence of adequate notice about their existence and actual or reasonably likely use by law enforcement, this Article proposes a way for Congress to create a mechanism to ensure that it receives such notice.


Mobile phones communicate by radio signal with a wireless carrier's network of cellular base stations or "cell sites." These cell sites are generally located on cell towers that serve geographic areas of varying sizes. (26) The regular communication between phone and cell sites enables the carrier to route calls, text messages and Internet data to and from a subscriber's mobile phone. To facilitate this process, cellular phones periodically register themselves with the nearest cell site so that the network can connect incoming calls and text messages to the subscriber's phone. (27) This registration process, as well as the act of making a call or transmitting data, automatically generates location data of varying degrees of precision. (28) Government agencies can compel a provider to disclose location data, whether the data was automatically generated by the wireless carrier in the normal course of business or specifically created in response to a surveillance request to "ping" a phone. (29) Such "carrier-assisted surveillance" can reveal a phone's historical, current, or prospective location (e.g., real-time tracking), (30) as well as other types of data, such as numbers called (31) and the addresses of web pages viewed from a mobile device. (32)

Carrier-assisted surveillance is not, however, the only means through which law enforcement can acquire such information. By impersonating a cellular network base station, a StingRay--a surveillance device that can be carried by hand, installed in a vehicle, or even mounted on a drone (33)--tricks all nearby phones and other mobile devices into identifying themselves (by revealing their unique serial numbers) just as they would register with genuine base stations in the immediate vicinity. (34) As each phone in the area identifies itself, the StingRay can determine the location from which the signal came. (35) The StingRay and other similar devices also have the capacity, if so configured, to intercept data transmitted and received by the phone, including the content of calls, text messages, numbers dialed, and web pages visited. (36) This process is accomplished without any visual indication to the target that she is under surveillance or any mediating involvement on the part of the carrier whose network the StingRay is impersonating. (37) In circumstances where the government either cannot acquire, or chooses not to compel, assistance from a provider, the StingRay may be the surveillance technique of choice. (38) Moreover, unlike carrier-assisted surveillance, in which the third-party provider necessarily has knowledge of surveillance performed and copies of records disclosed at the request of law enforcement, the unmediated nature of the StingRay dictates that only the operator of the device has: (1) knowledge that an interception ever took place; (39) and (2) or access to the information intercepted. Thus, to the extent that telephone companies are able to act as a proxy for their customers' privacy interests and may "push back" against overbroad or otherwise improper government surveillance, (40) no such advocate exists for the target when a Stingray is used. In short, the unmediated nature of StingRay technology makes it essentially "invisible" in operation and leaves behind no retrievable trace that is subject to future detection. (41)

Consider, for example, a situation where law enforcement agents can physically identify a target during the course of an investigation, but do not know the telephone she is currently using, perhaps because the target frequently cycles through disposable "burner" cell phones. (42) Investigators can position a StingRay in the vicinity of the target to capture the unique serial number of the target's phone. (43) In this case, law enforcement collects the identifying data in real-time because the StingRay, masquerading as the cell site with the strongest signal, (44) receives the information immediately and directly as it is communicated by the mobile phones, leaving no trace of the interception with the third party provider. (45) Moreover, while law enforcement may only seek to identify or locate the target's mobile device, a StingRay will also, as a matter of course, collect data from many other mobile devices in the surrounding area. (46)


Perhaps the most disconcerting aspect of the Section 215 metadata program to some surveillance scholars, beyond the sheer volume of information that was collected about hundreds of millions of Americans' domestic communications, is that a common sense reading of Section 215 does not support the government's interpretation that such broad, indiscriminate collection is permissible. (47) Indeed, one lawmaker who was an author of the PATRIOT Act has stated, "the government must request specific records relevant to its investigation.... To argue otherwise renders the provision meaningless.... It's like scooping up the entire ocean to guarantee you catch a fish." (48) The government's interpretation of intelligence authorities, where we have come to expect (if not accept) a lack of transparency with respect to the type and scope of collection allowed under various statutes, is not, however, the only area where such opacity exists. The StingRay, a surveillance technology that is used not only by the intelligence community, but also by the military and law enforcement agencies, (49) raises some of the same transparency issues. Indeed, the StingRay's capacity for invasive surveillance (i.e. sending signals through walls and into homes (50) and overbroad collection of innocent third party information (51)) could well provoke the same kind of surprise and dismay with respect to the government's interpretation of the Pen/Trap statute as sufficiently authorizing its use. This Part will describe those issues after first discussing real-time cell phone tracking as an example of how surveillance methods can fall into interpretive gaps within and between statutes.

A. Real-time Cell Phone Tracking and Secrecy

In the context of criminal investigations, there are only two statutory authorities that explicitly authorize the interception of communications information in real-time: the Wiretap Act (52) and the Pen/Trap statute. (53) Consequently, when the government wants to use a new surveillance method to collect data in real-time, it must first determine whether the technology or acquisition method fits under these existing statutory collection authorities. It must also conduct a Fourth Amendment analysis in order to determine if a search warrant must first be obtained. Cell phone location tracking represents one example of how the government analyzes and implements a real-time law enforcement collection method that has not been explicitly authorized by Congress.

It has already been described in the literature (54) and documented to a recent Congress (55) that nothing in the Electronic Communications Privacy Act (ECPA), which includes both the Wiretap Act and Pen/Trap statute, (56) articulates a legal standard Congress intended the government to meet before acquiring real-time cellular location data (i.e. tracking a mobile device in real-time) from a carrier. Indeed, the only hint from Congress suggesting a standard for law enforcement access to real-time location data is found in the Communications Assistance for Law Enforcement Act (CALEA), whose limited prescription instructs that "any information that may disclose the physical location of [a telephone service] subscriber" may not be acquired "solely pursuant to the authority for pen registers and trap and trace devices." (57) So CALEA points only to the insufficiency of a Pen/Trap order to support a government request for real-time or "prospective" (as opposed to "historical") location data. It provides, however, no specific affirmative guidance as to what level of process would provide sufficient support.

Left without explicit direction from Congress, DOJ created the controversial "hybrid-order" theory by stitching together the elements of a Pen/Trap order and an 18 U.S.C. [section] 2703(d) order for the disclosure of stored electronic communications found in ECPA's Stored Communication's Act (SCA). (58) Since at least 2005, criminal investigators have applied for both types of orders from judges when seeking to compel carriers to track a cellular phone in real-time. (59) Over time, however, some magistrate judges have accepted this hybrid theory and some have not. Those who have rejected the hybrid theory have required law enforcement agents to apply for a warrant pursuant to Rule 41 of the Federal Rules of Criminal Procedure. (60)

The appropriate standard for law enforcement access to real-time location data is, however, still an open question for both Congress and the courts. In the interim, a patchwork of non-binding magistrate and district court decisions has emerged, (61) with only one federal circuit court addressing the issue. (62) For now, the state of the law can be described fairly as a chaotic, "inconsistent legal landscape" that provides no clarity for law enforcement, courts, criminal defense attorneys or those citizens and advocacy organizations interested the protection of privacy. (63)

Scholars and some courts have criticized the hybrid theory on a number of grounds, ranging from its constitutionality (64) to whether, notwithstanding the constitutional question, Congress would have intended to permit the government's joining of historical and real-time surveillance statutes to authorize law enforcement access of real-time location data. (65) Absent better direction from Congress with respect to the appropriate standard for law enforcement access to real-time location data, the government would need, however, to arrive at some view of the appropriate process to follow when engaging in this form of surveillance. Considering that DOJ has used the hybrid theory to acquire real-time location data since at least 2005, that wireless carriers receive tens of thousands of court orders requiring the disclosure of location data per year, (66) and that, to date, there is still no real clarity in the law, it is fair to argue that judicial review has not adequately tested whether the government's hybrid theory: (1) fully complies with the Fourth Amendment; (67) (2) is consistent with congressional intent; or even (3) is consistent with the plain meaning of the relevant statutes.

Magistrate Judge Stephen Wm. Smith, an early critic of warrantless real-time tracking, (68) offers an important perspective on why appellate review of real-time location tracking and other types of government surveillance subject to ECPA is a rare occurrence: for the most part, the government is the only party with the ability and potential incentive to appeal unfavorable judgments. (69) ECPA surveillance orders are issued ex parte and often remain sealed long past an investigation's end. (70) A target of a sealed ECPA order is thus unlikely to become aware of the government's acquisition of her information unless an investigation proceeds to charges. It is at that point, as a criminal defendant, that a target can challenge the ECPA order. if an investigation never proceeds to an indictment, the innocent target will never learn that a third party disclosed her information to the government. (71) Moreover, while the third party provider receives the order compelling disclosure of information, such disclosure order is often accompanied by a gag order. (72) The third party provider could challenge the gag order, as well as the primary disclosure order, but instances where companies have "pushed back" against law enforcement ECPA orders in criminal investigations have not, to date, resulted in a steady stream of appellate court review. (73) In sum, as Judge Smith observes, "[t]hrough a potent mix of indefinite sealing, nondisclosure (i.e. gagging), and delayed-notice provisions, ECPA surveillance orders all but vanish into a legal void." (74)

The issues identified by Judge Smith lend discomfiting credence to Justice Alito's recent observation that, "[i]n circumstances involving dramatic technological change, the best solution to privacy concerns may be legislative." (75) But for the legislature to act, it must, at a minimum, have accurate information about how government agencies interpret their existing surveillance authorities, as well as the nature of new, unregulated surveillance technologies now in use. Judge Smith notes that, although the location tracking of cell phones first came to Congress' attention in 1994, nearly two decades have passed without any amendment to ECPA clarifying the appropriate law enforcement access standard. (76) While there is rarely one reason for why Congress is or is not able to pass legislation on a particular issue, one important factor affecting Congress' ability to legislate in the area of law enforcement access to location data is that Congress has not had current, accurate data on the nature and extent of cell phone surveillance for many years. (77) As we will discuss below, the StingRay presents even greater challenges to transparency and congressional awareness of government surveillance.

B. The StingRay and Secrecy

Much less is known about law enforcement use of StingRays in criminal investigations than is known about more traditional cell phone location tracking. What little is known comes mostly from a limited number of magistrate judge opinions, a tenacious criminal defendant seeking discovery in his own prosecution, (78) and a few obscure DOJ guidance documents. (79) This section discusses DOJ's interpretation of the Pen/Trap statute as authorizing law enforcement use of StingRays. It argues that, given the StingRay's powerful, unmediated and largely indiscriminate surveillance capabilities, a common sense reading of the text does not provide adequate notice to legislators that the Pen/Trap statute purportedly authorizes law enforcement use of a StingRay in criminal investigations. Such lack of notice, when compounded with the propensity for ECPA orders to vanish into a legal void (80) without revealing how DOJ and magistrate judges are interpreting surveillance authorities, severely restricts (even undermines) the ability of Congress to conduct meaningful oversight of government surveillance and to regulate new surveillance technologies and methods.

The crux of our argument is not that it is impossible to read the plain text of the Pen/Trap statute as being applicable to the StingRay but that, as collection capabilities expand in power and scope (as we have seen occur with the NSA's domestic telephony data collection program), government lawyers may interpret the text of statutes to authorize greater surveillance powers than a plain reading of the text would disclose or suggest. Moreover, through examining two magistrate court opinions discussing StingRay technology, we will illustrate the limited ability magistrate judges have to restrain government power when there is no statute directly authorizing or limiting a surveillance method or technology. First, however, we will discuss the parameters of the Pen/Trap statute itself.

The Pen/Trap statute authorizes law enforcement agencies, upon obtaining a Pen/Trap order from a court, to compel providers to disclose, in real-time, various types of transactional information pertaining to wire or electronic communications. (81) The statute references a "telephone line or other facility to which the pen register or trap and trace is to be attached or applied," (82) and the standard for such issuance is extraordinarily low. (83) indeed, the government need only certify that the information "likely to be obtained is relevant to an ongoing criminal investigation." (84)

Assuming that the magistrate judge finds that the Pen/Trap statute authorizes the kind of collection that the government seeks, then, upon such certification, the court must grant the application. (85) It is for this reason that at least one circuit court has characterized the role of magistrate judges in such instances as being "ministerial in nature." (86) In other words, when granting the Pen/Trap order, the magistrate does not examine or analyze whether there are sufficient facts to support the government's certification that the information sought is relevant to an ongoing criminal investigation.

The Pen/Trap statute arguably authorizes the government to compel production of a broad array of both telephony and Internet data. (87) While DOJ's public manual on "Searching and Seizing Computers" does not give a detailed list of all of the specific types of transactional information that can be obtained with a Pen/Trap Order, it notes that the statute's reference to "'dialing, routing, addressing [and/or] signaling information' encompasses almost all non-content information in a communication." (88)

Given the broad array of real-time data that the Pen/Trap statute appears to authorize the government to compel from a third party provider, does a plain reading of the statute suggest that it also authorizes law enforcement to use a sophisticated technological device to impersonate a cell site operated by the target's cellular provider and collect such information, without the assistance of a third party? Moreover, does a plain reading of the statute suggest that law enforcement is authorized to use a device that may, in the process of collecting data about a target's device, also collect data about a significant number of innocent third parties, depending on how the device is used? (89) In posing these questions, we are moving beyond a mere inquiry as to whether the statute conceivably authorizes this type of surveillance to ask whether legislators are on notice that the statute can be, and is being, interpreted to authorize surveillance that potentially impacts so many innocent people.

1. The 1995 Digital Analyzer Magistrate Opinion

The first published opinion (and one of only a few that are public) that helps to address some of these questions came in 1995, when Magistrate Judge Edwards took the position that no authority, including the Fourth Amendment, either authorizes or limits the government's use of a far more rudimentary predecessor of the StingRay (90)--a device commonly referred to as a "digital analyzer" or "TriggerFish" (91)

In this case, the government applied for a Pen/Trap order to employ a digital analyzer to intercept the signals from cellular phones used by five named subjects in a criminal investigation. (92) Magistrate Judge Edwards found, however, that because the digital analyzer was not intended to be, nor could it be, physically attached to the cellular phone, the Pen/Trap statute was not applicable to its use. (93) Judge Edwards also found, pursuant to Smith v. Maryland, (94) that the government's use of a digital analyzer raised no Fourth Amendment concerns. (95) This ruling was consistent with DOJ's position, first publically documented in 1997, that neither the Fourth Amendment nor any statutory authority prohibited its use of the digital analyzer, as long as the acquisition of non-content data did not involve the assistance of carriers. (96) While not a legal requirement, DOJ still advised prosecutors to seek a Pen/Trap order when using a digital analyzer as a Pen/Trap device. Thus, in 1995, it appears DOJ sought court authorization via the Pen/Trap statute merely "out of an abundance of caution." (97)

Although ultimately ruling that the Pen/Trap statute did not regulate--and thus did not prohibit--government use of a digital analyzer, the judge expressed serious reservations about its capabilities and use. Specifically, the judge expressed concern about the potential intrusion upon the privacy of innocent third parties. That is, if the court authorized the government to use a digital analyzer to identify the particular phones used by known targets, such an order would essentially permit agents to sweep the relevant surrounding areas and intercept signals emitted from all phones in those areas. Indeed, Judge Edwards recognized that "depending upon the effective range of the digital analyzer, telephone numbers and calls made by others than the subjects of the investigation could be inadvertently intercepted." (98) Moreover, although the agents were not seeking to intercept communications content, the digital analyzer was capable of being used for that purpose. (99)

The court also noted that its authorization could permit the government to collect data about large numbers of phones without any recordkeeping or reporting requirements, thus preventing effective congressional oversight of the surveillance tool. (100) The court contrasted this lack of record production with the statutory reporting requirements to Congress in the Pen/Trap statute, such as "the use of court orders that identified particular telephones and the investigative agency" and "periodic reports to Congress stating the numbers of such orders." (101) Noting these differences and others, (102) the court stated that the government's application "would not insure sufficient accountability." (103)

The court's reasoning appears to illustrate broader concerns about a circumvention of congressional authority that would occur if the court granted the government's request, even "in an abundance of caution." By granting an order pursuant to a statute whose definitional elements did not conform to the surveillance technique at issue, the court risked giving: (1) a potentially incorrect interpretation of a statute; or worse (2) judicial approval of a surveillance technique that Congress appeared neither explicitly to authorize or prohibit under the statutory authority presented in the government's application--all without the corresponding accountability mechanisms that Congress mandated in the statute cited in the government's application.

Though it expressed concern about the surveillance capabilities of this technology, the court could not restrain its use by law enforcement. Ironically, the court's denial of the government's application likely reinforced DOJ's stance that it did not need any court authorization for future use of a digital analyzer. (104) At least in this instance, however, it was clear to the court exactly what it was being asked to authorize. A more recent opinion suggests that courts are being asked to grant applications for the use of StingRays in criminal investigations without appropriate knowledge about what the technology actually does--information that is necessary to determine both whether the Pen/Trap statute authorizes its use and whether the use of a StingRay constitutes a search under the Fourth Amendment.

2. 2012 StingRay Magistrate Opinion

By 2005, if not earlier, DOJ had adopted the position that the Pen/Trap statute, as amended by the 2001 PATRIOT Act, "appears to encompass all of the non-content information passed between a cell-phone and the provider's tower." (105) Accordingly, DOJ advised prosecutors to seek a Pen/Trap order for all non-content data that agents acquired directly. (106) This was a significant change to DOJ's earlier 1997 guidance, which had interpreted the law to permit unmediated surveillance (e.g. performed directly via cellular surveillance technology rather than with the assistance of carriers) without the necessity of a Pen/Trap or other court order.

In 2012, a federal magistrate judge from Texas issued an order denying an application submitted by agents from the Drug Enforcement Agency for the use of a StingRay. (107) The case involved a surveillance target that switched from using a phone known to agents to an unknown phone. (108) The government therefore sought a Pen/Trap order "to detect radio signals emitted from wireless cellular telephones in the vicinity of the [Subject] that identify the telephones." (109) The agents submitted their application pursuant to the Pen/Trap statute (110) and 18 U.S.C. [section] 2703(c)(1), a provision of ECPA's Stored Communications Act, (111) and the government informed Magistrate Judge Owsley that it was "based on a standard application model and proposed order approved by [DOJ]." (112)

Since the subject was known to law enforcement (whereas the phone number the target was using was unknown), agents planned to identify the phone by capturing device identification data "at various locations in which the [subject's] telephone [would] reasonably [be] believed to be operating." (113) After reviewing the application, the judge conducted an ex parte hearing where an agent leading the investigation indicated that the "equipment designed to capture the cell phone numbers was known as a '[S]ting[R]ay.'" (114)

Ultimately, the court denied the government's application. (115) Judge Owsley expressed concern that the application did not adequately explain the technology or "how many distinct surveillance sites they intend[ed] to use, or how long they intend[ed] to operate the [S]ting[R]ay equipment to gather all telephone numbers in the immediate area." (116) Moreover, the court noted that no explanation was given, either in writing or verbally, as to what would be done with the "innocent ... information" collected from the phones of uninvolved individuals who just happened to be in the vicinity of the surveillance target. (117) Finally, the court expressed concern that neither the prosecutor nor the DEA agent appeared to understand the technology at issue and "seemed to have some discomfort in trying to explain it." (118)

At a 2013 symposium at Yale Law School, Judge Owsley suggested that:

   The practice of the feds' not making clear the planned use of a
   StingRay when seeking surveillance authorization could be
   widespread.... I may have seen them before and not realized what it
   was, because what they do is present an application that looks
   essentially like a pen register application.... So any magistrate
   judge that is typically looking at a lot of pen register
   applications and not paying a lot of attention to the details may
   be signing an application that is authorizing a Sting[R]ay. (119)

Indeed, a StingRay or similar tracking device appeared to be used in a case that made its way to the Seventh Circuit. (120) Because the circuit court opinion and underlying district court opinion (121) never refer to such a device, whether by a specific or generic name or other identifying description, the only real indication that the Pen/Trap order authorized law enforcement use of a StingRay-type device was through DOJ's disclosure of a copy of the opinion in response to a Freedom of Information Act (FOIA) request regarding StingRay devices filed by one of this Article's authors. (122) Moreover, additional documents obtained from an ACLU FOIA request indicate that Pen/Trap applications presented to magistrate judges in the Northern District of California did not make law enforcement's intended use of StingRays "explicit." (123)

Notwithstanding his broader concerns, Judge Owsley's decision to deny the application appears to stem from a definitional problem he identified in the Pen/Trap statute that, ultimately, the government did not adequately address. While recognizing that the PATRIOT Act broadened the Pen/Trap definitions, "amplifying] the various types of information that are available such as routing and signaling information," (124) Judge Owsley read language contained in Section 3123(b)(1) of the statute as "straightforward in that a telephone number or similar identifier is necessary for a pen register." (125) Accordingly, he found that the language in the statute "mandate[s] that this Court have a telephone number or some similar identifier before issuing an order authorizing a pen register." (126) Because the government did not provide any support to the contrary suggesting that the statute authorized collection of non-content data from unidentified devices, Judge Owsley denied the application without prejudice. (127)


Together, these two magistrate opinions (one pre- and the other post-PATRIOT Act) raise questions as to whether the Pen/Trap statute can properly be interpreted as authorizing the use of a StingRay or similar unmediated surveillance technology to acquire non-content communications data. Beyond parsing the statutory language, however, these opinions illustrate how the government seeks to accommodate the use of new and powerful surveillance technologies through aggressive interpretation of existing statutory language that neither directly authorizes nor prohibits their use.

More critically, for legislators looking at how they can create or improve a process for regulating and overseeing law enforcement use of new surveillance technologies and collection methods, the 1995 digital analyzer opinion illustrates the limited ability a magistrate judge has to constrain government surveillance that is neither authorized nor prohibited directly by statutory language. The court's sense of futility is manifest in the conundrum of whether it is appropriate to authorize government use of a new technology merely "in an abundance of caution." By denying the government's Pen/Trap application essentially on the grounds that it was unnecessary, Judge Edwards likely reinforced DOJ's view that no form of judicial oversight was necessary for law enforcement use of the surveillance technology. While this may have been the appropriate legal answer, it raises significant oversight concerns.

As previously indicated, when a digital analyzer or StingRay collects data, no corresponding third party records are created--the information intercepted is in the sole possession of the agents using the StingRay. (128) If there is no judicial oversight, then there is no trace or record of StingRay surveillance in a particular case other than law enforcement's own elective record keeping systems. While it is not impossible for the information to surface as part of the discovery process of a criminal prosecution, (129) such disclosures would depend on how discovery rules were applied in particular cases. In other words, records production in the context of the criminal discovery process is not a solid, reliable avenue for legislators to learn, in a timely fashion, about law enforcement use of new surveillance technologies and government legal interpretations supporting their use.

Conversely, the 1995 digital analyzer opinion also illustrates how congressional authority and oversight can be short circuited if a court, "in an abundance of caution," grants an application for use of a new invasive surveillance technology when that method is not directly authorized by statute and is not apparent to a legislator through a common sense reading of the statutory text. In this instance, a court risks giving judicial imprimatur to a new surveillance technology in the context of a system in which, as Judge Smith has explained, appellate review of ECPA ex parte surveillance orders is rare. (130) The appellate process is thus unlikely to expose law enforcement use of the technology or government interpretations of the statutes purportedly authorizing such use within anything approaching a timely notice period that would facilitate either congressional oversight or legislative action. (131) Moreover, as Judge Owsley has noted, it is possible that magistrate judges have authorized law enforcement use of StingRays in various cases without even knowing or understanding what they were authorizing. If true, this practice adds an additional layer of complication to congressional notice and oversight, since only elements of the Executive branch may know about law enforcement use of new surveillance technologies in criminal investigations.


After many months of almost weekly disclosures about classified NSA intelligence programs, we have begun to understand how, at times, government agencies will interpret statutory language to authorize bulk, indiscriminate collection in a way that is not apparent from a plain reading of the statutory text. While some members of Congress were aware of this type of collection in the context of the Section 215 metadata program, we have argued that the StingRay has significantly expanded the government's surveillance capabilities in criminal investigations while it has, nevertheless, gone largely unnoticed and unregulated. Indeed, a plain reading of the Pen/Trap statute would not put a legislator on sufficient notice that the government was interpreting the statute to authorize StingRay surveillance. (132) While we are not suggesting that no congressional staffer or Member of Congress is aware of the StingRay family of technologies and their capabilities, there is no public evidence that Congress has formally evaluated the privacy implications of law enforcement use of such unmediated, indiscriminate surveillance methods. (133) Moreover, given the scant number of published cases illustrating a court's analysis and interpretation of statutes that may authorize law enforcement use of the StingRay family of technologies, it would be unrealistic to expect judicial review to facilitate meaningful notice to Congress in anything approaching a timely fashion. (134) The StingRay, therefore, illustrates a larger gap in congressional oversight insofar as new, invasive surveillance technologies and collection methods not directly authorized by Congress can be used, often for decades, without any reliable notice to Congress about their use. Simply put, before Congress can begin to regulate new surveillance technologies and methods, it must have some notice of their nature and actual or likely use. An authoritative, reliable mechanism is needed to produce information that can provide such notice.

As part of the Administration's response to the summer 2013 Snowden disclosures, which began with the revelation of the 215 metadata program, President Obama announced his intention to convene an outside group of experts to conduct a full review of NSA surveillance programs and issue a report about how these programs impact security, privacy and foreign policy. (135) This expert panel has since issued its report, which provided, among other things, recommendations about possible reforms to the Section 215 metadata program. (136) A far more detailed report focusing on the Section 215 metadata program was subsequently released by the Privacy and Civil Liberties Oversight Board (PCLOB). (137) The PCLOB is an independent, bi-partisian Executive Branch agency authorized by Congress in the context of the "war on terrorism" to ensure, among other things, that "liberty concerns are appropriately considered in the development and implementation of laws, regulations, and policies related to efforts to protect the Nation against terrorism." (138)

While Congress has currently authorized PCLOB oversight only of government efforts to protect the nation from terrorism (and the recent PCLOB report on Section 215 and the operations of the FISC is part of that oversight effort), there is no impediment to congressional expansion of the PCLOB's mandate to review, advise, and counsel more generally on surveillance technologies and methods that permeate current criminal investigations (or those that could reasonably be predicted to do so in the future), even if they do not necessarily relate to government efforts to protect the Nation against terrorism. Congress could, for example, task the PCLOB with studying the specific surveillance technologies and methods that are in use or reasonably likely to be used by various law enforcement agencies in criminal investigations and the legal authorities the government believes authorizes or, conversely, does not prohibit their use. The goal of such an assessment should be the production of written recommendations by the PCLOB to Congress specifying which technologies are in need of direct authorization or prohibition, and which statutory authorities need to be updated and amended to accommodate or prohibit their use.

In service of this goal, Congress should further direct the PCLOB to write public reports at regular intervals (which could also, if necessary, include non-public or classified addenda) making such recommendations and directly identifying privacy issues associated with law enforcement's use of new surveillance technologies or collection methods, as well as old technologies like the StingRay, whose current or likely future use gives rise to new privacy concerns. (139) Moreover, for purposes of conducting the investigation and analysis leading to its written recommendations, Congress should both direct and empower the PCLOB to talk with all relevant government agencies, surveillance technology manufacturers, outside technologists and any other parties or entities that would provide relevant information. (140)

The StingRay and its capabilities invoke several important questions that should guide the PCLOB in making recommendations about technologies and methods Congress should regulate directly. This brief list is illustrative, though in no sense exhaustive, of some inquiries the PCLOB should consider:

(1) Is the technology or technique in question invasive of common and legal conceptions of personal privacy?;

(2) Does it challenge a common-sense understanding of the statutory text that the government interprets to authorize its use?;

(3) Is it an indiscriminate collection method that intercepts data from innocent cell phones in the coverage area of the mobile device being targeted?;

(4) Is it an unmediated surveillance method that leaves no trace of its use beyond internal government agency records?; and

(5) Might it, without such oversight or other regulation, otherwise remain hidden from any degree of public perception or scrutiny?

These questions suggest what we would describe as a minimal examination of the privacy implications and potential need for regulation of law enforcement use of any new technology or novel technique, particularly an unmediated surveillance device like the StingRay. The lines of inquiry encompass the interaction between a specific surveillance technology or technique and relevant cultural norms regarding the expectation of privacy, the specific legal interpretations the government would employ to support its use, the scope of the data collection involved, as well as the physical index, if any, present during its use and the record or trace, if any, it leaves afterwards.


Knowledge and perception must precede oversight. Congress cannot understand or regulate a surveillance technology it cannot "see" clearly, whether through conceptual understanding of its operation before the fact or actual analysis of the history of its use. The StingRay is a law enforcement surveillance technology that has, for nearly two decades, evaded direct congressional scrutiny, much less informed authorization or regulation. Moreover, the StingRay illustrates how law enforcement agencies can use surveillance technologies and methods, justified by expansive and potentially problematic interpretations of existing statutes, for years before they ever come to the attention of Congress--if they ever do. We have thus argued that an authoritative, reliable procedure must be established to put Congress on notice about the functions, capabilities and historical use, if any, of new surveillance technologies and methods if the law is ever to keep pace with technological change. As they are for the newest of technologies, the need for such procedures is applicable even to decades-old technologies like the StingRay, whose expanding surveillance capabilities, combined with its increasing frequency of use by law enforcement at ever-descending costs, (141) invoke privacy implications not heretofore appreciated.

Indeed, we are entering an era where law enforcement agencies have the technical capability to hack into the computers and phones of surveillance targets, allowing them covertly to activate webcams and microphones, search through documents, and obtain a person's web browsing history. (142) These capabilities have been acquired and used without any public congressional hearings or other open debate, much less any explicit legislative mandate. As it hints at technological disruptions to come and how the legal disorder they bring may unfold, the StingRay offers strong evidence that now is the time to establish a reliable mechanism that will be a continuous source of useful guidance to Congress as more powerful surveillance tools emerge and evolve to challenge the very notion of privacy as they strengthen the ability of the government to monitor and control the lives of its citizens. For more new and powerful surveillance tools shall certainly emerge in the coming age than are "dreamt of in [our] philosophy" of personal privacy or its current practical expression in our laws. (143)

Stephanie K. Pell * & Christopher Soghoian **

16 Yale J.L. & Tech. 134 (2013)

(143) "There are more things in heaven and earth Horatio, Than are dreamt of in your philosophy." WILLIAM SHAKESPEARE, HAMLET act 1, sc. 5.
