The list that nobody knew existed
In 2019, after Lambda Legal's consent judgment in Foster v. Andersen forced Kansas to allow trans residents to correct the gender marker on their birth certificates, the state complied. Hundreds of people updated their documents. Thousands more updated their driver's licenses at the Division of Vehicles.
What none of them knew is that the Kansas Office of Vital Statistics quietly began internally flagging every such amendment with a label distinct from routine clerical corrections, and the Division of Vehicles created a parallel internal marker called "gender reclassification." Neither was disclosed publicly. Neither had any stated purpose beyond administrative record-keeping. For seven years, the list just sat there.
On January 28, 2026, the Kansas legislature passed SB 244 via a "gut-and-go" substitution sponsored by Sen. Mike Thompson. The bill redefined "gender" as sex assigned at birth, directed the state to invalidate and reissue driver's licenses, directed the Office of Vital Statistics to invalidate birth certificates, banned restroom use mismatched to birth sex, and — the operative feature — created a $1,000 private right of action that any citizen could bring against any suspected violator. Governor Laura Kelly vetoed it on February 13. The legislature overrode her on February 17–18 by a House vote of 87–37. The law took effect February 26.
Within days, approximately 1,700 trans Kansans received mailed letters notifying them that their driver's licenses had been invalidated. The mechanism was only practical because the state already had the list. The registry — built for an entirely different administrative purpose years earlier — was the targeting infrastructure.
The story broke not in The New York Times but in Prism Reports and ScheerPost on April 2 and April 5, in reporting by independent journalist Aleksandra Vaca at the Transitics Substack. Vaca's line is the thesis of this article: "The whole thing about surveillance is that it happens as long as people don't notice. Only when Kansas revoked IDs did people ask how."
Lambda Legal Senior Counsel Omar Gonzalez-Pagan called SB 244 a "bounty hunter regime." The ACLU filed Doe v. Kansas in Douglas County District Court; a temporary restraining order was denied March 10. An evidentiary hearing on the temporary injunction is set for September 29, 2026. In the meantime, those 1,700 people have to keep living.
And Kansas isn't alone. Internal documents obtained by Texas Public Radio's Lauren McGaughy show the Texas Department of Public Safety collected 110 trans Texans' names and license numbers between August 2024 and August 2025 — license clerks scanned IDs and forwarded them to a dedicated internal email account. DPS refused to explain. Tennessee's HB 0754/SB 0676 passed the state House in March; it requires gender clinics to report every patient's age, county, sex assigned at birth, diagnosis, medications, procedures, provider, and mental-health data to the state Department of Health within 15 days, with the Department obligated to publish the data annually beginning December 31, 2026. In Indiana, AG Todd Rokita has intervened in seven pending court-ordered gender-change cases, calling the amended certificates "falsified records." Nine states now ban gender-marker changes on driver's licenses outright.
The pattern is not that states are suddenly building lists. The pattern is that lists are always being built, as a routine byproduct of administration. The political moment determines what they are used for.
The breach that nobody is talking about
On October 21, 2024, the SafePay ransomware group walked into the network of Conduent Business Solutions, a govtech contractor whose "Government Solutions" division runs Medicaid eligibility, SNAP benefit processing, child support systems, unemployment insurance, and public-health call centers on behalf of 46 U.S. states. Conduent processes approximately $85 billion in government disbursements and 500 million Medicaid claims per year. The intruder sat inside the network for 84 days — 3.5 times the 2024 industry median dwell time — before Conduent detected the intrusion on January 13, 2025.
Conduent began notifying affected individuals nine months later, in October 2025. The count started at 4 million. It climbed to 10 million. Then, through a cascade of state-by-state HIPAA filings, to 25 million and counting — Texas: 15.4 million. Oregon: 10.5 million. Washington: 76,000. South Carolina: 48,000. New Hampshire: 10,000. Maine: 378. Massachusetts and California filings are pending. The final number will rise further.
The stolen data is catastrophic: names, addresses, dates of birth, Social Security numbers, medical and treatment information, health insurance claims data, and banking information. The exfiltration volume was approximately 8 terabytes.
On February 12, 2026, Texas Attorney General Ken Paxton issued Civil Investigative Demands to Blue Cross Blue Shield of Texas and Conduent. His statement: "The Conduent data breach was likely the largest breach in U.S. history. If any insurance giant cut corners or has information that could help us prevent breaches like this in the future, I will work to uncover it." Whether Paxton is right depends on where the count finally lands. As a candidate for the worst healthcare data exposure ever recorded, Conduent is still well short of the 2024 Change Healthcare breach (192 million) — but the final Conduent count is still climbing.
The population inside the dataset is not a random cross-section of the country. It skews overwhelmingly toward low-income, disabled, elderly, and immigrant families — the people enrolled in Medicaid and SNAP in the first place. These are the Americans least able to afford credit monitoring, identity-theft lawyers, or private banking alternatives. The breach's true cost will be measured in their lifetimes.
The case is consolidated as In re: Conduent Data Security Litigation in the U.S. District Court for the District of New Jersey, before Judge Michael A. Hammer, with a Plaintiffs' Steering Committee of 8 attorneys including DiCello Levitt partner Corban Rhodes. Thirty-five lawsuits and climbing.
And Conduent is not the only vendor failure. On March 26, 2026, NYC Health + Hospitals disclosed an 11-week network compromise that ran from November 25, 2025 to February 11, 2026. NYC H+H is the nation's largest public safety-net health system — 11 acute-care hospitals, 45,000 employees, 1 million+ patients annually, 84% Medicaid or Medicare, 190+ languages served. The entry vector, per the official notice, was a third-party vendor whose identity has not been publicly disclosed. Exposed data included names, Social Security numbers, medical records, driver's license numbers, insurance details, payment information — and biometric data: fingerprints and palm prints.
Fingerprints and palm prints cannot be changed. A lifetime credential is now a lifetime liability.
The Medicaid pipeline
In July 2025, the Centers for Medicare and Medicaid Services signed an Information Exchange Agreement with ICE. Under that agreement, ICE gained access to names, addresses, dates of birth, ethnicity, and Social Security numbers of approximately 79 million Medicaid enrollees. A federal court blocked the transfer in 20 plaintiff states in August 2025; a later ruling allowed "basic" Medicaid data sharing to resume.
What nobody publicly admitted, until the case of M-J-M-A v. Wamsley, was what happened next to the data.
In December 2025, at an evidentiary hearing in that federal class-action challenging ICE raids in Woodburn, Oregon, an ICE Fugitive Operations Unit officer was deposed under oath. Asked to describe the Palantir tool the officer used to pick targets, he testified that it generates a map populated with pins — each pin a potential target — with a confidence score out of 100 predicting how likely the person is to live there. The officer explained the workflow:
"It's kind of like Google Maps. You're going to go to a more dense population rather than, like, if there's one pin at a house and the likelihood of them actually living there is like 10 percent, you're not going to go there."
The tool is called ELITE — Enhanced Leads Identification & Targeting for Enforcement. It ingests HHS Medicaid enrollment data, IRS records, SSA data, DMV, DHS/USCIS immigration records, LexisNexis and Thomson Reuters commercial data, utility records, and ICE tip-line submissions. ICE agents can tap a single pin or draw a shape around an area to select every person inside it for enforcement. The officer in the Oregon deposition said he was under orders of eight arrests per team per day. A judge later ruled the Woodburn raids "violent and brutal" and unconstitutional, but the ruling did not shut down the tool.
The Electronic Frontier Foundation, in its January 15, 2026 report, summarized it cleanly: "ICE is using a Palantir tool that uses Medicaid and other government data to stalk people for arrest."
Palantir's contracts tell the scale. In April 2025 ICE signed a $30 million contract for ImmigrationOS, with related Investigative Case Management spending ballooning to $145 million. ELITE itself runs a separate ~$29.9 million line. In February 2026, DHS signed a $1 billion five-year blanket purchase agreement giving every DHS component — CBP, ICE, FEMA, CISA, TSA, Secret Service, Coast Guard — streamlined Gotham and Foundry access without separate procurement. Palantir's total federal contracts in 2025 nearly doubled year over year to $970.5 million. Its stock is up 130% and trading at roughly 80 times sales. The federal government is Palantir's primary growth engine, and it is buying what it cannot constitutionally seize.
The parts you didn't sign up for
Once you start looking for the pattern, it's everywhere.
The school camera is a deportation tool. An investigation by The 74 found that in a single month (December 2025 through early January 2026), 3,100+ police agencies conducted 733,000+ searches of school district camera data through Flock Safety's national network. Of those, 620 searches were immigration-related, by 30 agencies across Florida, Georgia, Indiana, and Tennessee. Civil immigration searches outpaced criminal immigration searches two to one. Parents signed off on Flock cameras as "lockdown safety" infrastructure. They bought an ICE pipeline with a school-district invoice. On February 26, 2026, California drivers filed a class action alleging Flock's "national lookup" feature gave out-of-state agencies access to SFPD's camera database 1.6 million times in seven months. An audit found 364,000 unauthorized searches against Ventura County cameras that were supposedly set to California-only. Mountain View, Ithaca, Syracuse, Berkeley, Santa Cruz, Lynnwood, Flagstaff, Bend, South Pasadena, Oxnard, Denver, Dunwoody, and more than twenty other cities have now either suspended or canceled their Flock contracts. But that only protects the cities that act.
The student tip is a doxxing honeypot. On March 18, 2026, a hacker using the alias "Internet Yiff Machine" released 93 gigabytes containing 8.3 million records from P3 Global Intel, the Navigate360 "anonymous tipline" platform used by 30,000+ K-12 schools including Miami-Dade, Philadelphia, Portland, and Denver Public Schools. The data spanned from February 1987 to November 2025. It included names, emails, phone numbers, dates of birth, home addresses, Social Security numbers, license plate numbers, criminal histories, and chat logs between tipsters and agencies — of both the tipsters and the people they reported on. Many of the tips concerned students in crisis: self-harm, suicide threats, bullying, potential violence. The hacker left a note: "Don't do the dirty work for the pigs." The marketing said "anonymous." The engineering said otherwise. Dubbed "BlueLeaks 2.0" after the 2020 police-data dump.
The AI scribe invents its own consent. In a lawsuit filed November 26, 2025 in California Superior Court for San Diego County (Saucedo v. Sharp HealthCare), plaintiff Jose Saucedo alleges that during a routine physical at a Sharp Rees-Stealy clinic in July 2025, Sharp's Abridge-powered ambient AI scribe recorded his entire visit without informing him or asking consent. When Saucedo later reviewed his patient-portal notes, they contained a boilerplate, AI-generated sentence stating he had been "advised" of and "consented" to the recording. He had not. The AI did not merely fail to get consent; it appears to have fabricated the paper trail showing consent had been obtained. The complaint covers a proposed class of 100,000+ California patients. Abridge is deployed in 150+ health systems, including Kaiser Permanente's 24,000 doctors across 40 hospitals, the largest gen-AI rollout in healthcare history, plus Mayo Clinic, Johns Hopkins, UPMC, Yale New Haven, Memorial Sloan Kettering, Duke. Abridge closed a $300M Series E in June 2025 at a $5.3 billion valuation.
The face-recognition lead is an arrest warrant. On July 14, 2025, Angela Lipps, a 50-year-old grandmother from Carter County, Tennessee — who told CNN she had "never been on an airplane, let alone to North Dakota" — was arrested at home on a North Dakota fugitive warrant. West Fargo Police had used Clearview AI to match the photo on a fake military ID used in a Fargo bank-fraud scheme, and Clearview had returned a probable hit for Lipps. Detectives "assumed wrongly" that the fake ID photo was a surveillance image of the actual suspect. Nobody verified. Nobody interviewed her. She spent 108 days in a Tennessee jail cell, was extradited to North Dakota on October 30, was finally interviewed by a Fargo detective for the first time on December 19, and had all charges dismissed on December 23 after her attorney Jay Greenwood produced bank and Social Security records showing she was 1,200 miles away buying cigarettes and depositing checks when the Fargo withdrawals happened. She was released Christmas Eve, with no money, no coat, and no way home. She lost her house. She lost her car. She lost her dog. Fargo had no formal facial-recognition policy until March 25, 2026 — days before CNN's story broke. Clearview now claims 50+ billion scraped face images. NIST's 2019 study found algorithms are 10 to 100 times more likely to misidentify Black or East Asian faces; of eight publicly documented facial-recognition wrongful arrests, seven of eight victims are Black. Lipps was the eighth.
The airport transit is now a password-extraction zone. On March 23, 2026, Hong Kong gazetted an amendment to the Implementation Rules of Article 43 of the National Security Law. Refusing to provide a password or decryption assistance under a national-security investigation is now punishable by up to one year in jail and a HK$100,000 fine. Providing false information: up to three years and HK$500,000. The rule applies to anyone — residents, visitors, and passengers in airport transit. Hong Kong International Airport handled 61 million passengers in 2025 and its transfer traffic surged 50.2% year over year. The US Consulate General Hong Kong issued a formal security alert to American citizens. Deloitte and KPMG now instruct executives flying through HKG to carry burner phones. Jimmy Lai, the 77-year-old founder of Apple Daily and a British citizen, was sentenced to 20 years on February 9, 2026; six Apple Daily editors received combined sentences exceeding 50 years. On February 26, the 69-year-old father of US-based activist Anna Kwok was jailed for 8 months for attempting to cancel his daughter's childhood insurance policy — the first prosecution of a family member for an overseas activist's actions.
The asylum fingerprint is a deportation warrant. On June 12, 2026 — 62 days from today — EU Regulation 2024/1358 transforms the EURODAC database from a 20-year-old fingerprint-comparison tool for Dublin asylum processing into a comprehensive "asylum and migration management" database with central storage of facial images, identity documents, nationalities, and application records. The minimum fingerprinting age drops from 14 to 6. The EU Fundamental Rights Agency, confronted with the possibility of using force on children to obtain the prints, stated in a formal opinion that it is "difficult to imagine a situation where the use of physical or psychological force to obtain fingerprints for Eurodac would be justified." UNICEF, IOM, and UNHCR issued a joint statement urging the EU to "exempt all children, no matter their age, from all forms of coercion." The EU passed the regulation anyway. EURODAC will interoperate with SIS, VIS, EES, ETIAS, and ECRIS-TCN through the Common Identity Repository — meaning a six-year-old fingerprinted at a Greek island reception facility will have a lifelong, EU-wide identity record tied to "irregular entry," queryable for return enforcement. Current Ukrainian beneficiaries of temporary protection are carved out until 2029. The rest of the world's children are not.
The encryption works. The cache leaks. On April 9, 2026, at federal trial in the Northern District of Texas, FBI Special Agent Clark Wiethorn testified (Exhibit 158, trial day 12) that examiners had extracted Signal messages from a seized iPhone via iOS's push-notification cache — specifically the DeliveredNotifications.plist and KnowledgeC.db artifacts that iOS maintains so the system can render lock-screen and Notification Center previews. The messages had been deleted. Disappearing messages had been enabled. The Signal app had been uninstalled. The preview text still sat in iOS's forensic-discoverable cache for weeks. Signal's encryption was never broken. The phone was the leak. The only reliable mitigation — Signal's "Notification Content: No Name or Content" setting — is not on by default, and almost nobody enables it.
The pattern
Eight stories. The same architecture.
In every case, a dataset collected for one stated purpose — birth-certificate administration, Medicaid eligibility, school safety, hospital authentication, tipline reporting, asylum registration, delivery notifications, driver licensing — has been re-purposed for something else entirely by an entity that held power over it. Sometimes the re-purposing was legal under the existing framework (Kansas SB 244, Palantir ELITE after court rulings). Sometimes it was an actual crime (Conduent's SafePay attack). Sometimes it was a bug (Flock's "national lookup" toggle). Sometimes it was designed that way (EURODAC 2.0's return-enforcement expansion). It doesn't matter which flavor it is. They all look identical from the other end of the pipe.
What they share is this: the people whose data was collected cannot take it back. There is no button in a privacy-policy dashboard that retroactively undoes a Texas trans registry, or evicts ICE from a Medicaid enrollment table, or uncaches a Signal message from iOS. The decision was made for them, in bulk, by default, years before the political consequences arrived.
And the consequences are arriving fast. Conduent notifications are still going out. EURODAC switches on in 62 days. The Kansas ACLU case is on hold until September 29. Tennessee's gender-clinic publication starts December 31. FISA Section 702 expires in nine days — and 98 members of the Congressional Progressive Caucus have formally bound themselves to oppose any reauthorization without a warrant requirement, while Senators Wyden and Lee's Government Surveillance Reform Act attempts to close the data broker loophole that lets ICE buy what Carpenter would require a warrant to seize. Nobody knows if it passes.
There is a historical parallel worth pausing on. In 1943, the Dutch resistance bombed the Amsterdam civil registry office to destroy the index that the Nazi occupation was using to find Jews. Hans de Zwart wrote, years later: "During World War II, we did have something to hide." The architect of that index was not a Nazi. It was a Dutch civil servant named J.L. Lentz who had built the system before the war as an administrative improvement. The IBM punch cards that sorted the data were manufactured by Dehomag, IBM's German subsidiary, and ran on neutral census infrastructure. The lesson is not that databases cause genocide. The lesson is that the existence of a database is a decision, made by the builder, about whose power it will eventually serve. Who holds the database at any given moment decides what it is.
What permissionless data has to mean
The engineering answer is not "better privacy policy." Privacy policy is what produced this pattern. Purpose limitation, opt-in consent, data minimization pledges, and privacy impact assessments were the architecture that let every one of these datasets exist in the first place. They are also what let every one of them be repurposed. Policy failed not because it was too weak, but because it was the wrong kind of defense. It's a promise. Promises are revoked by whoever holds the keys.
The defense that survives a second administration has four properties:
- Don't collect what you can't protect from future repurposing. If a dataset's second use would be catastrophic for the people in it, the dataset should not exist in a form that makes the second use possible. A Kansas vital-statistics system should not have a schema field that encodes "gender marker changed, previous value on file." A Medicaid eligibility system should not have an API that another agency can query. A school camera should not be federated into a national law-enforcement network. The engineering decision to build these systems in centralized, queryable, schema-rich form was made without considering who would eventually hold the keys.
- If you must collect it, don't centralize it. Every Conduent-scale breach is an argument for splitting data across independent operators and programs. There is no reason a single private contractor should process Medicaid for 46 states. There is no reason one national license-plate-reader network should exist. The Kansas DMV's marker and the Kansas Office of Vital Statistics' marker should never have been in the same queryable system. Distributed storage dramatically raises the cost of a "draw a shape around the neighborhood" query.
- Cryptographic guarantees beat policy guarantees. The only protections that survive a change in administration are the ones that are enforced in code. Client-side encryption with keys the service doesn't hold. Data that is deleted not just from an index but from every backup on every vendor. Peer-operated infrastructure where the operator does not physically possess the data it would need to hand over. Warrant canaries and reproducible builds that make silent compromise detectable.
- The operator has to be structurally incapable of producing what it doesn't collect. Privacy policy asks operators not to sell data. The right goal is for operators to be unable to sell data, because the data doesn't accumulate on their side in the first place. This is the design principle of peer-operated networks, end-to-end encrypted messaging with zero metadata retention, and zero-knowledge credential systems. It is the opposite of the design principle of Conduent, Palantir ELITE, Flock Safety, Navigate360 P3, and NYC Health + Hospitals' centralized biometric stores.
URnetwork against the centralization pattern
URnetwork was designed on principle #4. It is not a messenger, a database, or an identity service — it is the network substrate underneath them. But because it is a peer-operated overlay rather than a vendor-operated service, it does not accumulate user data that any of the above mechanisms could later consume.
No central database of users. Every hop in URnetwork's routing path is a real consumer device belonging to a real participant who operates the network in exchange for a share of its revenue. There is no single entity holding a user list, a traffic log, or a subscriber profile. The warrant canary publicly commits that no keys have been handed over, no interception equipment installed, no encryption weakened. When the canary stops being updated, users will know.
No subscriber identity. The free tier provides 50 GiB per month with no account, no email, no identity. UR Pro is $5/month or $40/year with no KYC. Payouts to providers go out in USDC on Polygon or Solana — the payment rails themselves cannot be subpoenaed for a subscriber list because there is no subscriber list.
Transport indistinguishable from the web. The protocol ships three transports — QUIC/TLS, TCP/TLS, and WebRTC/dTLS — all of which are also spoken by ordinary web browsers. A government or ISP cannot fingerprint the traffic without blocking the open web. This is the property that keeps URnetwork functional in the places other infrastructure fails.
Distributed routing and zero server-side visibility. The performance-auctioned multi-hop routing shards traffic across multiple providers simultaneously. The encrypted audit log is designed so providers throw away their keys after each payout cycle — the keys are only derivable from a SHA-256 hash of a TLS client random supplied by the counterparty, making bulk extraction computationally intractable. "No central visibility into user traffic" is not marketing copy; it is the engineering invariant the operator has imposed on itself.
Open source, reproducibly built. The client is listed on F-Droid with builds independently reproduced from source by F-Droid maintainers and verified bit-for-bit against the published artifacts. A government that ordered URnetwork to insert a backdoor would have to change the source code in a way that anyone auditing the build could detect. The reproducible-build property turns the entire community into a tripwire.
350,000+ people, 100+ countries. The network operates because its participants run it. That is not a rhetorical point — it is a structural property that makes the network fundamentally different from a vendor-hosted service. BringYour (the company behind URnetwork) can be sued, subpoenaed, or sanctioned, and the network keeps routing traffic, because the network is the participants, not the company.
The honest caveat
Peer-operated infrastructure does not fix the datasets that already exist. It does not retroactively delete 25 million Conduent records, clear 1,700 Kansans from a registry, or remove Medicaid data from Palantir ELITE. Those datasets exist and will continue to exist until they are forced to be deleted — which, for many of them, will be never. The argument for permissionless infrastructure is not retroactive. It is prospective. It is about the datasets that are being designed and deployed right now.
Every medical system choosing a new EHR. Every city choosing a new camera vendor. Every EU member state implementing EURODAC 2.0. Every state building a new benefits eligibility system. Every school district signing a new tipline contract. Every AI scribe vendor writing a new template for "AI-generated consent language in the medical record." Each of those decisions is a future Kansas registry, unless someone makes a different decision now.
The people being harmed by the current pattern are the people who were always going to be harmed first: trans Kansans, low-income Medicaid enrollees, asylum seekers, Black grandmothers matched to strangers by a scraped face database, Palestinian aid workers whose employers were told to hand over staff biodata, undocumented parents whose kids' school cameras feed an ICE dashboard, Hong Kong journalists carrying a phone through an airport. The harm is always downstream of the design decisions they weren't in the room for.
What you can do
Run a URnetwork node. Download the app. Read the protocol. Verify the build. Enable provider mode so a participant in Iran or Hong Kong has one more residential relay in the set of paths they can route through. Buy a URnode if you want a whole-home appliance that runs the network on your behalf. Each of these is a small action against a very large pattern, and small actions are how large patterns fail.
But the deeper ask is this: when you design a system that touches other people's data, assume that you will not be the last person to hold the keys. Assume the next administration will be the worst possible administration. Assume the next CEO will be the worst possible CEO. Assume the next breach will happen during the worst possible week. Then design for that. Not for the dataset you want to build. For the dataset you will refuse to collect, because the second life would be worse than the first.
Kansas kept a list since 2019. It was just an administrative system. Until it wasn't.
References (71 sources)
References
Kansas SB 244 and trans registries
- Kansas Senate Bill 244 — Wikipedia overview
- ACLU of Kansas — Understanding SB 244
- NBC News — Kansas revokes licenses of 1,700 transgender residents
- NPR — Kansas revokes transgender licenses
- Transitics / Aleksandra Vaca — Kansas secretly built a list
- Prism Reports — Red states are making lists of trans people
- ScheerPost — "Kansas Was Going To Be The First Domino That Fell"
- KUT — Texas DPS collecting data on transgender drivers
- Tennessee HB 0754 — Gender clinic data publication bill
- Indiana Capital Chronicle — AG Rokita intervenes in gender-change cases
- ACLU of Kansas — Doe v. Kansas case page
- Lawrence Times — TRO denied March 10
Conduent breach
- HIPAA Journal — Texas AG investigates 25M+ Conduent breach
- Malwarebytes — The Conduent breach: from 10M to 25M and counting
- Texas AG press release — demands info from BCBS and Conduent
- TechCrunch — Conduent data breach grows to 25M
- State of Surveillance — Conduent 25M largest in US history
NYC Health + Hospitals breach
- NYC Health + Hospitals — Notice of Data Breach (official)
- HIPAA Journal — NYC H+H discloses 11-week network compromise
- Edelson Lechtzin class action investigation
Palantir ELITE
- EFF — ICE using Palantir tool that feeds on Medicaid data
- State of Surveillance — ELITE "kind of like Google Maps" deposition testimony
- Fortune — ICE alleged to use Palantir ELITE tracking Medicaid data
- 404 Media — ELITE: The Palantir app ICE uses to find neighborhoods to raid
- Racket — Palantir's freaky ELITE app
- SiliconANGLE — DHS awards Palantir up to $1B
- KFF — CMS-ICE Medicaid data sharing implications
School surveillance, Flock Safety, and Navigate360
- The 74 — ICE taps into school security cameras via Flock
- State of Surveillance — Flock Safety class action lawsuit
- Courthouse News — California drivers accuse Flock Safety
- Education Week — Navigate360 P3 breach
- The Breach — BlueLeaks 2.0 P3 Global Navigate360 breach
- DDoSecrets — BlueLeaks 2.0 archive
- NPR — Cities canceling Flock contracts
Sharp HealthCare AI scribe lawsuit
- KPBS — Sharp HealthCare secretly recorded exam room conversations
- MobiHealthNews — Sharp HealthCare ambient AI lawsuit
- Medscape — Sharp HealthCare sued over AI scribe consent
- TechCrunch — Abridge $300M Series E at $5.3B
- Kaiser Permanente — 24,000-doctor Abridge rollout
Angela Lipps and Clearview
- CNN — Tennessee grandmother jailed 5 months after AI facial recognition
- Reason — Fargo refuses to apologize for jailing Tennessee grandma
- State of Surveillance — Grandmother jailed 108 days after facial recognition
- NIST — Study on demographic effects in face recognition
Hong Kong NSL password amendment
- HK Government Gazette — 2026 Implementation Rules for Article 43
- US Consulate Hong Kong — Security alert 2026032601
- HKFP — New offence requiring suspects to hand over passwords
- Al Jazeera — Hong Kong grants police power to demand phone and computer passwords
- HKFP — 8 months jail for father of wanted activist Anna Kwok
- Human Rights Watch — Jimmy Lai sentenced to 20 years
EURODAC 2.0
- EUR-Lex — Regulation (EU) 2024/1358 full text
- European Parliament — Recast Eurodac Regulation
- EDRi — Warnings against mass surveillance in Eurodac
- UNICEF/IOM joint statement on coercion of children
- FRA Opinion on Eurodac
FBI Signal push notification cache
- 404 Media — FBI extracts deleted Signal messages from iPhone notification database
- 9to5Mac — FBI used iPhone notification data to retrieve deleted Signal messages
- Tech Times — Deleted doesn't mean gone
FISA 702 sunset
- Congress.gov — S.4082 Government Surveillance Reform Act of 2026
- Wyden press release — Government Surveillance Reform Act
- Congressional Progressive Caucus — 98 Democrats oppose reauthorization
- EFF — Our privacy cannot afford a clean extension of Section 702
FBI raid on Hannah Natanson
- CPJ — FBI searches Washington Post reporter Hannah Natanson's home
- CNN — Judge bars DOJ from searching Natanson devices
- RCFP — Judge rejects DOJ request to search reporter's devices
- Privacy Protection Updates Act — Wyden/Balint
Historical parallel
- 1943 bombing of the Amsterdam civil registry office — Wikipedia
- IBM and the Holocaust — Wikipedia
- Hans de Zwart — "During World War II, we did have something to hide"
URnetwork
- URnetwork — Home
- URnetwork — Protocol
- URnetwork — App download
- URnetwork — URnode ($145 pre-order)
- URnetwork — About
- URnetwork — F-Droid listing (2026.1.7)
- URnetwork — GitHub build (reproducible)