AnoniumVPN All articles
Privacy & Policy

A Decade of Watching: How U.S. Surveillance Has Quietly Transformed Since the NSA Leaks

AnoniumVPN
A Decade of Watching: How U.S. Surveillance Has Quietly Transformed Since the NSA Leaks

Photo: digital surveillance concept with data streams and government building silhouette, via mundocolorirdesenhos.com.br

In June 2013, a former NSA contractor named Edward Snowden handed journalists at The Guardian and The Washington Post a collection of documents that would reshape how the world thought about digital privacy. The programs revealed—PRISM, XKeyscore, MUSCULAR, and others—demonstrated that the United States government had constructed a surveillance architecture of breathtaking scope, one capable of collecting and analyzing the communications of millions of people, including American citizens, with minimal judicial oversight.

The public outrage was immediate. Congressional hearings followed. Technology companies issued carefully worded denials. Civil liberties organizations filed lawsuits. And then, gradually, the news cycle moved on.

What did not move on was the surveillance itself.

What the Snowden Documents Actually Revealed

To understand where American surveillance stands today, it is worth revisiting what was disclosed eleven years ago. The PRISM program, perhaps the most widely reported revelation, enabled the NSA to collect internet communications—emails, video chats, photographs, stored documents—directly from the servers of major technology companies including Google, Microsoft, Apple, and Facebook. Participation by these companies was compelled under Section 702 of the Foreign Intelligence Surveillance Act (FISA), a legal authority that, while nominally targeting foreign nationals, inevitably swept up enormous quantities of American communications through what analysts called "incidental collection."

XKeyscore was described internally as the NSA's most expansive tool for searching internet data, capable of querying content and metadata from communications captured at collection points around the world. Analysts could, according to the documents, search through vast databases of emails, social media activity, and browsing history with minimal supervisory approval.

The scale was not the only revelation. The legal framework enabling these programs—largely constructed in the aftermath of the September 11 attacks and operating under classified court orders from the Foreign Intelligence Surveillance Court (FISC)—had been interpreted so broadly by the executive branch that it bore little resemblance to what Congress had publicly debated or what the American public had understood to exist.

The Legislative Response: Reform That Wasn't

The political response to the Snowden disclosures produced the USA FREEDOM Act of 2015, which was widely described as the most significant reform to U.S. surveillance law in decades. The act ended the NSA's bulk collection of domestic phone metadata under Section 215 of the Patriot Act—a program that had required telecommunications companies to hand over call records in bulk on a rolling basis.

Civil liberties advocates acknowledged the reform while arguing that it was, at best, a partial measure. Section 702 of FISA—the authority underpinning PRISM and other programs targeting foreign communications—remained largely intact. That authority was reauthorized in 2018, again in 2023, and most recently in April 2024, when Congress passed a reauthorization that expanded the definition of "electronic communications service providers" required to assist in surveillance. Critics noted that this expansion potentially captures a far wider range of businesses and individuals than previous iterations of the law.

The Foreign Intelligence Surveillance Court, which provides judicial oversight of these programs, continues to operate almost entirely in secret. Its rulings are classified, its proceedings are one-sided, and its approval rate for government surveillance requests has historically hovered near 100 percent. Whether this reflects the rigor of government applications or the structural limitations of a court that hears only one side of every argument is a question that remains difficult to answer from the outside.

How Surveillance Has Evolved Since 2013

In some respects, the surveillance ecosystem that Snowden revealed has been constrained at the margins. In other respects, it has grown considerably more sophisticated and pervasive.

Facial recognition technology has expanded dramatically across federal, state, and local law enforcement agencies. The Government Accountability Office reported in 2021 that at least 20 federal agencies used facial recognition systems, with the FBI's database containing hundreds of millions of images. Unlike the programs revealed by Snowden, much of this expansion has occurred with minimal public debate and no comprehensive federal legal framework governing its use.

Data broker ecosystems have emerged as a parallel surveillance infrastructure that government agencies have learned to exploit without triggering Fourth Amendment scrutiny. Because commercial data brokers collect and sell personal information—location data, purchasing history, social media activity, and more—voluntarily shared with apps and platforms, law enforcement agencies can purchase this data rather than subpoena it, sidestepping judicial oversight entirely. The Office of the Director of National Intelligence acknowledged this practice in a 2023 report, describing the commercial data market as a significant source of intelligence on Americans.

Social media monitoring by federal agencies has become routine. Immigration and Customs Enforcement, the FBI, and the Department of Homeland Security have all contracted with vendors to monitor social media platforms at scale, tracking keywords, accounts, and networks of association. The legal basis for this monitoring, and its scope, remains largely opaque to the public.

Stingray devices—cell-site simulators that mimic cell towers to intercept communications and identify nearby devices—have proliferated among local and federal law enforcement agencies. Their use is governed by an inconsistent patchwork of state laws and agency policies, with limited transparency about deployment frequency or targets.

What Everyday Americans Are Unknowingly Exposing

The average American does not think of themselves as a surveillance subject. They are not a foreign national, a suspected terrorist, or a political dissident. They have, as the saying goes, nothing to hide.

This framing misunderstands both the nature of modern surveillance and the breadth of what is being collected. Your smartphone generates a continuous stream of location data. Your browser history reflects your health concerns, financial anxieties, political interests, and personal relationships. Your purchasing patterns reveal behavioral tendencies that can be modeled with surprising accuracy. The apps on your phone may be transmitting data to dozens of third parties simultaneously, many of them unknown to you.

None of this requires a targeted surveillance order. Much of it is collected passively, aggregated commercially, and available for purchase or legal compulsion by any government agency with sufficient interest and resources.

The practical implication is that the distinction between "targeted" and "mass" surveillance has become increasingly difficult to sustain. When data about virtually everyone is available in commercial databases, the decision to surveil a specific individual requires only a query, not a new collection effort.

Why Proactive Privacy Measures Matter More Than Ever

The legislative and judicial mechanisms designed to constrain government surveillance have proven to be imperfect instruments. Courts have been slow to extend constitutional protections to data voluntarily shared with third parties—a doctrine known as the "third-party" rule that was established long before the smartphone era. Congress has repeatedly reauthorized surveillance authorities with modest modifications rather than fundamental reform. Executive branch agencies have interpreted their legal authorities expansively and disclosed the results reluctantly.

In this environment, waiting for institutional protection is a strategy with a poor track record. The most reliable safeguard available to individual Americans is the adoption of privacy tools that limit what can be collected in the first place.

A VPN cannot prevent a government agency from obtaining data that you have already voluntarily shared with a platform or app. What it can do is encrypt your internet traffic, mask your IP address, and prevent your internet service provider—which is legally required to retain and potentially disclose your browsing data—from building a detailed record of your online activity. When combined with other privacy-conscious practices, this represents a meaningful reduction in exposure.

The conversation that Edward Snowden started in 2013 was never really about him. It was about the architecture of a surveillance state that had grown faster than the laws designed to govern it, and the gap between what Americans believed about their privacy and what was actually true. Eleven years later, that gap has not closed. If anything, it has widened.

Staying informed is the first step. Acting on that information is the one that matters.

All Articles

Related Articles

That Free Latte Comes With a Side of Data Theft: The Uncomfortable Truth About Public WiFi