ZeroHour

Search: “evaluation”

9 stories

25 Years of Mass Surveillance Is Enough

Bruce Schneier and Cindy Cohn argue post-9/11 mass surveillance expanded far beyond its counterterrorism justification and should be reevaluated for costs to rights.

An essay by Bruce Schneier and Cindy Cohn (originally in Lawfare) traces the post-9/11 shift from targeted surveillance to mass collection of telephone and internet metadata. It cites the Section 215 bulk phone records program, struck down in interpretation by the Second Circuit in 2015 and curtailed by the USA Freedom Act, and the NSA's Upstream program under Section 702 of the 2008 FISA Amendments Act, which ended content searches in 2017. The authors note mass surveillance now serves routine law enforcement and immigration actions, with FBI Director Kash Patel confirming purchases of Americans' data from brokers, and private systems like Flock license plate readers and venue facial recognition feeding government access.

Schneier on Security · 2d agoPolicy & legal

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

The FCC proposed a public scorecard rating telecoms' anti-robocall effectiveness and removed 14 providers from US networks for compliance failures.

The Federal Communications Commission issued a public notice proposing a scorecard that would assess how effectively retail voice providers, including wireless, wireline and VoIP, prevent illegal robocalls, drawing on Robocall Mitigation Database filings, consumer complaint and enforcement data. The agency stressed it is not a rulemaking imposing new requirements, and it is seeking comment on scope, such as whether to focus on larger providers. The same day, the FCC removed 14 providers from the Robocall Mitigation Database for non-compliance, effectively requiring other US providers to block their traffic within two days.

CyberScoop · 14d agoPolicy & legal

US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate

US defense contractors report rising self-assessed CMMC Phase I scores while doubting the accuracy of those self-evaluations.

Self-assessment scores under the US Department of Defense's Cybersecurity Maturity Model Certification (CMMC) Phase I have reportedly reached an all-time high. Contractors themselves doubt whether these self-reported scores accurately reflect their real security maturity. The uncertainty highlights concerns about the reliability of self-assessments in the program's initial phase.

Infosecurity Magazine · 28d agoPolicy & legal

What the 3M ChatGPT case reveals about AI governance

3M litigation shows ChatGPT prompts can become discoverable evidence, forcing enterprises to govern AI conversation records.

In the Watson Grinding explosion litigation, an engineering expert retained by 3M had used ChatGPT, and a surfaced prompt asked the system to 'show how 3M is 0% at fault'; after an off-record deposition demand, more than 350 pages of previously unproduced ChatGPT material were provided. The author argues AI interaction histories are becoming part of decision records and discovery material, a trend the American Bar Association has already examined. Enterprises are urged to manage retention, ownership, sharing, and deletion of AI conversation logs across tools like ChatGPT, Copilot, Claude, and Gemini.

CSO Online · 3d agoPolicy & legal

A Secretive DHS ‘Predictive Policing’ Unit is Analyzing Americans’ Financial Habits and Pulling Them Over

404 Media reveals DHS Border Patrol's secretive Predictive Intelligence Targeting Teams (PITT) analyzing Americans' financial activity and feeding intelligence to local police for traffic stops.

404 Media identified Predictive Intelligence Targeting Teams (PITT) in the Spokane Sector (Washington) and Laredo Sector (Texas), which review law enforcement-sensitive databases including Americans' financial activity and pass intelligence to local police. In one case, a PITT analyst flagged financial patterns associated with narcotics activity, leading Montana Highway Patrol to stop a driver for an obstructed license plate and charge him with DUI and possession with intent to distribute. CBP declined to say what financial data is monitored or whether warrants are obtained; the program extends AP's earlier reporting on ALPR-based predictive policing.

404 Media · 9d agoPolicy & legal

Risky Bulletin: Russia starts blocking DoH and DoT

Russian users report blocks on DoH and DoT servers, including Cloudflare 1.1.1.1 and Google 8.8.8.8, in an apparent censorship crackdown.

Russian internet users began reporting failures connecting to DNS-over-HTTPS and DNS-over-TLS servers, suggesting a government crackdown on the two privacy protocols. The blocks reportedly cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 resolvers; Roskomnadzor has not officially confirmed the action. The agency tested a similar block in March on Beeline's network and had named DoH for blocking as early as 2021. The bulletin also briefly notes state-sponsored phishing of EU officials, a DDoS against Norway's Digdir, the ReliaQuest/ShinyHunters dispute, and older ransomware and breach disclosures.

Risky Business News · 22d agoPolicy & legal1

US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks

Trump signed a national security memorandum letting vetted private US cybersecurity firms run government-approved offensive cyber operations against transnational criminal organizations.

The August 13 memorandum creates a program managed by the National Coordination Center covering Cyber Surveillance Operations and Cyber Effects Operations against Cyber-Enabled Transnational Criminal Organizations, explicitly excluding entities that are parts of foreign governments. DOJ and DHS executive directors must co-approve every operation in writing, with extra authorization for operations raising laws-of-armed-conflict questions. Participating firms must pass vetting, annual evaluations and hold a $1 million bond or escrow. Operating procedures are due within 60 days, and the unresolved CFAA exemption question is addressed by requiring direct government control.

Security Affairs · Aug 14, 2026Policy & legal

Trump taps cyber firms to go on offensive against criminals

Presidential memorandum allows vetted private companies to conduct offensive cyber operations against transnational cybercrime with advance DOJ and DHS approval.

A presidential memorandum released Wednesday lets vetted US companies partner with the Justice and Homeland Security departments on offensive operations and surveillance targeting transnational cybercrime, fraud and predatory schemes, with written pre-approval required for every operation. Operations may not cause loss of life or rise to the level of use of force or armed attack under international law. Participating firms face penalties of at least $1 million for contract violations, must disclose all contractual relationships, and face annual evaluation, while agencies have two months to develop participation standards. The move builds on a March executive order; the White House says Americans reported $20.8 billion in cyber-related losses last year.

The Record · Aug 13, 2026Policy & legal

Trump turns to private sector in offensive hacking operations memo

Trump signed a national security memorandum authorizing vetted private companies to conduct offensive cyber operations against transnational criminal organizations under federal oversight.

The memorandum creates a federal coordination center program authorizing 'Participating Companies' to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign cyber-enabled transnational criminal organizations. Participating firms must contract with the Justice Department or Department of Homeland Security, undergo vetting, and comply with existing laws including the Computer Fraud and Abuse Act. The White House cited sustained fraud and cyber-enabled campaigns from TCOs as justification, building on a March fraud-focused executive order. Experts including Veracode co-founder Chris Wysopal called it a major shift in U.S. cyber policy, though it stops short of broader 'hack back' proposals.

CyberScoop · Aug 13, 2026Policy & legal1