Three deadlines
At 11:59 p.m. Eastern on Monday, April 20, Section 702 of the Foreign Intelligence Surveillance Act will cease to be law unless Congress acts. On Wednesday, April 22, Chinese Telecom-issued SIM cards across an as-yet-undetermined subscriber base will stop supporting international roaming services, per a leaked text message and an internal Shaanxi Telecom directive ordering infrastructure operators to "eliminate any form of circumvention business." On Tuesday, April 28, federal civilian executive branch agencies must finish remediating CVE-2026-32201, the actively exploited SharePoint spoofing vulnerability that Microsoft disclosed yesterday and that the Cybersecurity and Infrastructure Security Agency added the same day to its Known Exploited Vulnerabilities catalog.
Five days. Seven days. Thirteen days. Three deadlines set by three different authorities under three different bodies of law. They are not coordinated. They do not describe the same event. But this week, for the first time in some years, they describe the same question.
The question is what happens to a centralized communications or records infrastructure when the authority that owns it changes its mind about what to do with it. Section 702 was built for foreign intelligence. The FBI now queries it for domestic investigations. The Chinese carrier licensing system was built to connect Chinese citizens to the global internet. Beijing's regulators are now using it to sever that connection at the carrier layer. Microsoft SharePoint was built to host collaborative documents. It is presently running on enterprise networks that an unauthenticated attacker can reach, and the federal civilian branch has less than two weeks to shut that reach off before an incident report turns into a compromise notification.
Today's edition covers the three deadlines and the events surrounding them — Pasadena's audit hearing tonight, the Fourth Circuit's April 10 vacatur of the DOGE/SSA injunction, the Department of Health and Human Services' April 9 admission that it shared a "large and complex" Medicaid data set with Immigration and Customs Enforcement contrary to a federal court order, Tennessee's 24-to-7 Senate vote yesterday on a patient-reporting registry, and Virginia's bipartisan signing on Monday of a location-data sale ban. Seven separate news events in seven days. One pattern underneath.
Pasadena tonight
At 5 p.m. Pacific today, the Pasadena Public Safety Committee will hear the city's internal audit of its Flock Safety automated license plate reader program. The preliminary briefing finding, released in advance: "no evidence of misuse or unauthorized access." Pasadena Police Chief Gene Harris will present. All 184,000 alerts generated in 2025 by the city's 61 Flock cameras were tied to documented case numbers. Access was limited to sworn officers, dispatchers, and crime analysts. Data retention was 30 days. The department plans to install 11 additional cameras, bringing the deployment to 72. Pasadena's overall crime clearance rate rose from 28.96 percent in 2023 to 35.26 percent in 2025. The audit does not claim that Flock caused the increase. It reports the correlation.
The audit is internally consistent with its scope. Its scope does not reach the network above it.
On April 3, 2026, the law firm Gibbs Mura filed an amended class-action complaint in San Francisco Superior Court alleging that Flock Safety permitted more than 1.6 million out-of-state searches of the San Francisco Police Department's automated-plate-reader database over a seven-month period, in violation of California's ALPR Privacy Act of 2015. The complaint does not allege that San Francisco officers misused the database. It alleges that the network layer above the department — the Flock National LPR Network, operational across more than 5,000 communities and 4,800 law-enforcement agencies, performing over 20 billion vehicle scans per month — produced the cross-jurisdictional sharing pattern that SB 34 forbids. The alleged violation is not the local officer's search. It is the architecture that made the out-of-state query possible from the moment the sharing was enabled.
On April 14, one day before tonight's hearing and eleven days after the amended complaint, Flock Safety announced a product called Audit Assistance via GlobeNewswire. It is described as a tool that "continuously monitors system activity and surfaces search patterns that fall outside an agency's typical usage." It is delivered to agency administrators. It is not a transparency tool for the public.
Across the 110 freeway in South Pasadena, the City Council reached the opposite conclusion in February 2026. Fourteen Flock cameras will be decommissioned. The city cited data-safety concerns after confirmed reports that Southern California Flock data had been accessed by federal immigration enforcement and by out-of-state police departments. Two adjacent cities, one vendor, opposite decisions. The difference is not policy quality. It is what each council decided the question was.
The record was patently false
On Friday, April 10, 2026, the U.S. Court of Appeals for the Fourth Circuit, sitting en banc, vacated a preliminary injunction that had blocked the Department of Government Efficiency from accessing the records of the Social Security Administration — records covering approximately 70 million Americans. The case is American Federation of State, County and Municipal Employees v. Social Security Administration, No. 25-1411. The majority held that the plaintiffs had not demonstrated irreparable harm.
Judge Robert King dissented. His dissent is unusual for a federal circuit court. SSA and the other defendants, King wrote, "provided patently false information to the district court in the preliminary injunction proceedings." Prior rulings, he continued, "were rendered on a materially erroneous record." The majority acknowledged neither finding. Four days later, on Tuesday, April 14, the U.S. District Court for the District of Maryland lifted its stay of the case and granted the plaintiffs' motion for discovery. The district court will now examine the record the Fourth Circuit said it could not examine — the record that the government itself, in a January filing, conceded had been incomplete.
The January filing said something specific. It said that a DOGE employee had signed an agreement to share SSA data with an unnamed political advocacy group that was seeking to overturn election results in certain states. The agreement, according to the filing, was not authorized through the normal SSA data-sharing review process. The filing did not specify the group. It did not specify the states. It said only that the arrangement existed. The majority in the Fourth Circuit held that the existence of the arrangement did not, standing alone, establish the irreparable harm the plaintiffs had claimed. Judge King held that the failure to disclose the arrangement when the injunction was originally litigated was itself the record problem.
This is what the April 14 discovery order reaches for. The plaintiffs will now be permitted to examine what DOGE accessed, when, with what authorization, and for what downstream uses. The 70 million beneficiaries whose records are at issue will not see the discovery themselves. Their data is already where it is. What the discovery can establish is only the chain of custody — who held the data when, and for what. Whether the data can be recalled from wherever it went is not a question discovery answers. Data does not unmove.
The SSA case is not an isolated instance. It is one of two parallel federal-records cases in the same 10-day window. The second sits in the Northern District of California.
The large and complex data set
On Thursday, April 9, in the matter of California v. U.S. Department of Health and Human Services, No. 25-cv-05536 (N.D. Cal.), the federal government acknowledged in a court filing that it had shared a "large and complex" set of Medicaid enrollee data with Immigration and Customs Enforcement. A coalition of 22 state attorneys general, led by California, had alleged the sharing violated a December 2025 order issued by Judge Vince Chhabria. That order had permitted ICE to pull only a narrow set of biographical fields — addresses, phone numbers, birth dates, and citizenship or immigration status — and only with respect to people whose lawful presence in the United States was not established. The order specifically barred collection on U.S. citizens and lawful permanent residents.
The April 9 filing did not contest the sharing. It disclosed it. What it did not disclose was how HHS had determined which enrollees qualified for the narrow permitted categories and which did not. The 22 states' allegation, in essence, is that HHS never made that determination — that the department shared Medicaid records in bulk and left the categorization to be performed on the other side of the transfer, by ICE, using the data that had already been shared. The data covers approximately 80 million enrollees nationwide. An enforcement hearing is scheduled for April 30.
The Medicaid data and the SSA data describe the same architecture. Records aggregated at a federal custodian for a specific statutory purpose. A subsequent executive-branch decision to make the aggregation available to a different agency, for a different purpose. A court order attempting to constrain the secondary use. A subsequent filing disclosing that the secondary use exceeded the order. In the SSA case, the disclosure was involuntary — forced by plaintiffs' discovery and a dissenting judge. In the Medicaid case, the disclosure was in a government filing that appears not to have volunteered the disclosure so much as memorialized it after the fact.
The architecture underneath both cases is not different from the architecture underneath Pasadena's Flock audit. Once aggregation has occurred, the question of what is done with the aggregation is not a question that any single audit can foreclose. Discovery can describe it. A court order can restrict it. A data-sharing agreement can formalize it. The aggregation itself is the precondition for all of these downstream actions. Aggregation is what makes the downstream possible.
State divergence
Two states voted on data aggregation this week. They went in opposite directions.
On Monday, April 13, Gov. Abigail Spanberger of Virginia signed SB 338. The bill bans the sale of precise geolocation data — defined as data capable of identifying a consumer's location within 1,750 feet — by any controller of personal data operating in the Commonwealth. The bill passed the Virginia General Assembly by unanimous, bipartisan vote at every stage. It takes effect July 1, 2026. Virginia becomes the third state to enact such a ban, joining Oregon and Maryland. Similar bills are pending in California, Connecticut, Massachusetts, and Vermont. Location data has served as the proxy field in federal immigration targeting workflows that, per OMB inventories and 404 Media reporting, have consumed data-broker feeds through Palantir's ELITE application.
On Tuesday, April 14, at 11:47 a.m. Central, the Tennessee State Senate voted 24 to 7 to pass SB 676. The bill requires health-care providers to report every transgender adult patient they treat — by age and date of birth, by sex assigned at birth, by county of residence, by medication, dosage, duration, and route of administration, by surgical procedure code and referral source, by provider contact and specialty, by visit date, by mental-health condition history — to a state agency. The sponsor was Sen. Brent Taylor of Memphis. The lone Republican no vote was Sen. John Stevens of Huntington. The House companion, HB 754, passed 70 to 21 with two abstentions on March 26. The Senate added two amendments — adding attorney-general investigative authority, striking a county-level public-release provision — and returned the bill to the House for reconciliation. Gov. Bill Lee has signed every LGBTQ-related bill sent to him in his governorship. His only veto was an unrelated parole-board matter in May 2025. Non-compliance penalties: $150,000 per clinic, six-month license suspension.
The two bills arrived at their respective governors' desks eighteen hours apart. One prevents a category of data from being assembled into a commercial market. The other compels a category of data to be assembled into a state archive. Both are matters of state law, passed by state legislatures, signed (or about to be signed) by state governors. The divergence is architectural, not partisan. Virginia's bill removes the aggregation. Tennessee's bill manufactures one. The federal courts, this week, are litigating what happens to aggregations already in place.
Five days: Section 702
Section 702 of FISA expires at midnight on April 20 unless Congress acts. The choice before Congress is binary. Either the statute is reauthorized in substantially its current form — an outcome the White House has been pushing for, led by Senior Adviser Stephen Miller and CIA Director John Ratcliffe — or the Government Surveillance Reform Act of 2026, S.4082, substantially alters it.
S.4082 was introduced on March 12 by Sens. Ron Wyden of Oregon and Mike Lee of Utah. Cosponsors include Sens. Cynthia Lummis of Wyoming and Elizabeth Warren of Massachusetts — a libertarian-right and progressive-left pairing that appears on Fourth Amendment questions and almost nowhere else. The House companion comes from Reps. Warren Davidson of Ohio and Zoe Lofgren of California, both of the House Judiciary Committee. The bill does four things. First: it requires the FBI to obtain a probable-cause warrant from the Foreign Intelligence Surveillance Court before querying the 702 database for a U.S. person. Second: it prohibits federal agencies from purchasing Americans' data from commercial brokers without a warrant, incorporating the Fourth Amendment Is Not For Sale Act. Third: it expands declassification requirements at the FISC. Fourth: it amends the Electronic Communications Privacy Act to require warrants for stored communications regardless of age.
The administration's argument, articulated by Ratcliffe in closed-door Senate briefings and reiterated publicly, is that Section 702 produces the majority of the articles in the President's Daily Brief — a claim first made by NSA Director Mike Rogers in 2017 congressional testimony and repeated by every subsequent Director of National Intelligence and Director of Central Intelligence. The intelligence value is represented as irreplaceable; a lapse, even brief, is represented as a gap adversaries would exploit. Speaker Mike Johnson has not publicly committed to a floor schedule. Senate Intelligence Committee Chairman Mark Warner and Vice Chairman Tom Cotton have supported reauthorization with limited procedural reforms and opposed the GSRA. No markup has been held on S.4082 in either chamber.
The reform bill's path to a floor vote in five days is, by conventional legislative standards, implausible. The clean reauthorization's path is the default. The default is what is on the clock.
The architectural fact underneath the debate is that Section 702 is not itself the surveillance. It is the legal authority to direct American electronic communication service providers to turn over the communications they hold. The providers hold the communications because the architecture of American internet and mobile services concentrates records at the carrier and platform layer. Salt Typhoon, the Chinese intelligence operation that penetrated at least nine U.S. telecommunications carriers between 2019 and 2024, reached the lawful-intercept infrastructure that 702 and its sister authorities rely on. The choke point designed for American intelligence was the choke point a foreign intelligence service exploited. Centralized access points do not select their users.
Seven days: the Locknet closes
On Wednesday, April 22, an as-yet-unspecified population of Chinese mobile subscribers will lose international roaming on their current SIM cards. The notification was a text message from China Telecom, disclosed on April 8, stating that SIM replacement would be the only remedy. A separate internal directive, attributed to Shaanxi Telecom and circulated to business customers by Qihang CDN, orders internet service providers to block all outbound connections beyond mainland China — including connections to Hong Kong, Macau, and Taiwan — and to eliminate what the directive calls "any form of circumvention business." The category includes commercial VPN services, proxy routing, and the "airport" intermediary services on which most Chinese users of circumvention tools rely.
The architectural posture this directive represents is different from earlier Chinese internet enforcement. Prior enforcement, concentrated at the user layer, depended on mass detection of circumvention traffic and prosecution of individual users and small operators. The new posture is infrastructure-layer. Licensed carriers, licensed data centers, and licensed ISPs face the sanction of permanent operating-license revocation for allowing circumvention traffic to transit their infrastructure. The enforcement target is not the user seeking to bypass the Great Firewall. The enforcement target is the operator who would provide the transit the user needs.
Researchers at Northeastern University have re-described the system in a framework they call "the Locknet" — replacing the "Great Firewall" metaphor, which implied a wall to be scaled, with a metaphor of water locks that can be opened and closed selectively, permitting some traffic in some conditions and none in others. What closes on April 22 is not a new lock. It is an existing lock being tightened by a directive at the infrastructure layer.
Russia's comparison is proximate and informative. On April 1, 2026, Russian authorities reportedly fully blocked Telegram — the country's most widely used messaging application — and on March 31, Digital Development Minister Maksut Shadayev announced that mobile operators could charge up to 150 rubles, approximately $1.80, per gigabyte for international data routed through VPNs beyond 15 gigabytes per month. The state-backed MAX messenger, widely believed to be monitored by the Federal Security Service, is pre-installed on all new devices sold in Russia. Since early March, partial mobile internet blackouts have hit central Moscow and St. Petersburg — prompting locals to fall back, in some reported cases, to pagers and paper maps. Kremlin spokesman Dmitry Peskov has publicly confirmed using his landline phone during the blackouts.
The Chinese directive and the Russian block differ in mechanism but not in premise. Both presume a compellable provider. The provider's cooperation is the unit of enforcement. The enforcement operates on the infrastructure because the infrastructure is reachable, named, and licensed. The user whose traffic is blocked is not the party compelled. The carrier is.
Thirteen days: the patch no one will finish
On Tuesday, April 14, Microsoft released patches for 167 common vulnerabilities and exposures. It was the second-largest Patch Tuesday release in the company's history, nearing the October 2025 record. Eight of the vulnerabilities are rated critical. Seven of those are remote code execution. Elevation-of-privilege flaws accounted for 57.1 percent of the batch.
Two of the vulnerabilities are zero-days. CVE-2026-33825 is an elevation-of-privilege flaw in Microsoft Defender, publicly disclosed before the patch but not yet exploited in the wild. CVE-2026-32201 is a spoofing vulnerability affecting Microsoft SharePoint Server 2016, 2019, and the Subscription Edition. CVSS 6.5. Low attack complexity. No authentication required. No user interaction required. Exploited in the wild.
CISA added CVE-2026-32201 to its Known Exploited Vulnerabilities catalog on April 14. Federal Civilian Executive Branch agencies are required under Binding Operational Directive 22-01 to remediate. The deadline is April 28. Fourteen days from the announcement. CISA's binding authority reaches approximately 100 civilian federal agencies and does not directly cover state and local governments, the defense industrial base, or private-sector operators. Much of the SharePoint install base sits outside the FCEB perimeter. For those operators, the CISA deadline is an advisory.
SharePoint is the enterprise substrate for document collaboration across American state and local governments, defense contractors, and a significant share of the private sector. A spoofing vulnerability on a public-facing SharePoint server is a foothold from which an attacker can move laterally into whatever the organization has made the server's adjacent ecosystem — identity federations, file shares, collaboration graphs, cached credentials. Thirteen days is the time federal civilian agencies have to shut the foothold. For the rest of the install base, there is no deadline. There is only the patch.
The architectural reading
Seven different technical systems have moved this week. The Flock National LPR Network aggregates 20 billion vehicle reads per month from more than 5,000 communities. The Social Security Administration's records custody covers 70 million Americans and, per the April 14 Maryland discovery order, may now be examined for the scope of the DOGE access. The CMS Medicaid enrollee database covers roughly 80 million enrollees and, per the April 9 HHS filing, has already been shared with ICE beyond the court-ordered scope. Tennessee's proposed patient registry compels a new category of health-care data into a state archive. Virginia's new law removes a category of location data from the commercial market. Section 702 of FISA is either reauthorized by April 20 in current form or altered by the GSRA. China's carrier licensing system will, by April 22, sever outbound international connectivity for an unspecified population of mobile subscribers. Microsoft SharePoint servers across the federal civilian branch must be patched by April 28 to close an actively exploited spoofing flaw.
These are seven different systems, built by seven different sets of engineers, in seven different jurisdictions, under seven different legal regimes, for seven different purposes. In the second week of April 2026, each is being reassigned, contested, or cut over. The common property is not the content of the data or the identity of the authority acting on it. The common property is that each system is centralized, aggregated into an addressable store, and operationally compellable by whatever authority has standing over its operator.
An alternative architecture is not a theoretical object. It is the architecture in which endpoints are not enumerable, in which no central provider holds the cross-system join key that commercial brokers monetize and subpoenas reach, in which traffic transits multi-party paths across nodes that no single operator controls and no single court order can compel. A system with no single compellable provider does not present the chokepoint on which the Shaanxi Telecom directive relies, the chokepoint on which the Section 702 authority relies, the chokepoint on which the CMS Information Exchange Agreement relied, the chokepoint on which Tennessee's reporting mandate relies, or the chokepoint that Salt Typhoon exploited. The alternative exists in partial deployment — Signal's metadata minimization, Matrix's federated servers, Tor's onion routing, Briar's mesh connectivity — and in URnetwork's residential-node transport, where the substrate over which messages travel is the device of a peer, not the facility of a carrier.
This is not a claim that any single piece of deployed alternative architecture would, standing alone, have prevented the seven events above. It is the claim that the events above describe, collectively, the cost of continuing to rent communications and records custody to compellable providers. The April 20 vote, the April 22 cutoff, and the April 28 remediation deadline are three surface events in one week. They are expressions of a design decision made decades ago. The decision was to concentrate. It has been consistent. What has changed this week is the volume of authorities using the concentration at once.
Pasadena's Council will not resolve the architectural question tonight. Congress will not resolve it by Monday. Beijing will not resolve it by Wednesday. The FCEB CIOs will not resolve it by the 28th. The architectural question is the question underneath all four. The next clock starts on the 29th.
References (3 sources)
Sources
- American Federation of State, County and Municipal Employees v. Social Security Administration, No. 25-1411 (4th Cir. en banc, April 10, 2026); D. Md. April 14, 2026 order granting discovery.
- California v. U.S. Department of Health and Human Services, No. 25-cv-05536 (N.D. Cal., HHS filing April 9, 2026).
- Tennessee SB 676 / HB 754 legislative record; Senate vote April 14, 2026 at 11:47 a.m. Central; House vote 70-21-2 March 26, 2026.
- Virginia SB 338, signed by Gov. Abigail Spanberger April 13, 2026; effective July 1, 2026.
- 50 U.S.C. § 1881a (Section 702 of FISA); S.4082, Government Surveillance Reform Act of 2026, introduced March 12, 2026.
- Reforming Intelligence and Securing America Act (RISAA), Pub. L. 118-49 (April 20, 2024).
- Pasadena Public Safety Committee Meeting, April 15, 2026, agenda and briefing materials; Chief Gene Harris Flock Safety audit report.
- Flock Safety class action, amended complaint filed April 3, 2026, San Francisco Superior Court (Gibbs Mura).
- Flock Safety, "Audit Assistance" product announcement via GlobeNewswire, April 14, 2026.
- LAist, "South Pasadena cancels Flock Safety contract over privacy concerns," February 2026.
- Microsoft Security Response Center, April 14, 2026 Patch Tuesday release; CVE-2026-32201; CVE-2026-33825.
- Cybersecurity and Infrastructure Security Agency, Known Exploited Vulnerabilities catalog entry for CVE-2026-32201, April 14, 2026; Binding Operational Directive 22-01.
- Vision Times, "China's Telecom Crackdown May Block All Overseas Internet Access, Leaked Notice Suggests," April 11, 2026.
- China Digital Times, "Documents Raise Fear of Further Crackdown on Great Firewall Circumvention Tools," April 2026.
- Moscow Times, "As Kremlin Cuts Off the Internet, VPNs Become a Way of Life," April 3, 2026; "Russia's Digital Ministry Declares War on VPNs," March 31, 2026.
- Privacy and Civil Liberties Oversight Board, "Report on the Surveillance Program Operated Pursuant to Section 702 of FISA," September 2023.
- NPR, "Why Congress is fighting over a central tool of American surveillance," April 14, 2026.
- CNN Politics, "Inside the White House push for a clean 702 reauthorization," April 13, 2026.
- Consumer Reports, Virginia SB 338 signing announcement, April 13, 2026.
- NBC News, Tennessee SB 676 Senate passage coverage, April 14, 2026.
- KFF, "Potential Implications of the New Medicaid Data Sharing Agreement Between CMS and ICE," 2026.
- Government Executive, "States say ICE pulled Medicaid data despite court order," April 2026.
- Stateline, ICE Medicaid data access reporting, March 31, 2026.
- Axios, Flock Safety fundraising round reporting, April 13, 2026.
- Northeastern University research, "The Locknet," 2025-2026 framework description.
This is edition 2026-04-15-01 of the URnetwork daily privacy and internet freedom journal. The companion hot-takes document and the associated images and short-form video are published alongside.