Connect with us

Hi, what are you looking for?

Please enter CoinGecko Free Api Key to get this plugin works.

Investing News

Its Spying on Cato Exposed, the FBI Wants Its Database Names Kept Secret—That’s How Rights Violations Start and Endure

Patrick G. Eddington

On September 14, DC District Court Chief Judge James Boasberg ruled on the Cato Institute’s long-running Freedom of Information Act (FOIA) lawsuit against the FBI—a case seeking the Bureau’s records about Cato itself. The opinion is mixed, though the court ruled against the Bureau on several points.

Boasberg rejected as “flimsy” the FBI’s claims that revealing the location of the Los Angeles Field Office’s Counterterrorism Division that investigated Cato (revealed in January 2025 in documents at issue in the lawsuit) would assist others in circumventing the law.

He also invalidated the FBI’s withholding of press briefing materials:

The FBI briefly acknowledges its withholding of internal public-affairs news briefings, asserting that their disclosure would ‘reveal where the information was collected and what specific information was deemed relevant to the briefing.’ Driver Decl., ¶ 24. It entirely fails to explain, however, why those news briefings constitute a law-enforcement technique or how their disclosure would risk circumvention of the law. For those documents, the FBI did not properly invoke Exemption 7(E).

Unfortunately, Boasberg allowed the FBI to keep secret 59 pages of investigative records involving federal grand jury matters and “intelligence sources and methods”—all without revealing whether the investigation of Cato was formally closed or remains active.

Worse, another Boasberg holding likely enables a form of secrecy that American history demonstrates leads to constitutional rights violations at scale.

Boasberg accepted the FBI’s argument that the very names of its internal investigative databases are protected from disclosure as “law enforcement techniques” under the statute’s language.

Under FOIA Exemption 7(E), an agency may withhold records that would “disclose techniques and procedures for law enforcement investigations” where release “could reasonably be expected to risk circumvention of the law.” Genuinely novel and currently unknown investigative methods could, in fact, lose their value if telegraphed to the people they target.

But a database’s name is a noun, not a method.

The DC Circuit precedent the court relied on, Shapiro v. DOJ, 893 F.3d 796 (2018), holds that revealing how a database is “searched, organized, and reported” can expose techniques. That is a holding about methodology—the queries an agency runs and the results it treats as meaningful. It does not necessarily follow that the mere existence and name of a system reveal how the Bureau investigates.

The government’s own declarations in the Cato case make a different argument entirely: that naming a database would make it “an attractive target for compromise.”

That is a claim about network security (or lack thereof), not investigative tradecraft—and Exemption 7(E)’s “techniques and procedures” prong does not reach it. If it did, every named IT system the Bureau uses would be categorically secret, which no court has held and which would swallow the FOIA exemption’s own requirement that a technique be “generally unknown to the public.”

Boasberg sidestepped this by declining to engage a recent Third Circuit decision, Viola v. DOJ (Nov. 3, 2025), which held that an investigative practice the FBI “readily acknowledges” is “common enough to fall outside” 7(E)’s protection. Boasberg said he “need not resolve” whether Viola applied because he was bound to follow DC circuit precedent, “which has established that ‘the methods that the FBI uses to search [a] database and what results it considers meaningful … can reveal law enforcement techniques and procedures.’ ”

The secrecy-by-name practice is the specific mechanism by which the FBI has repeatedly escaped legal and constitutional control—and the harm it produces is not hypothetical. It is documented in the government’s own oversight records for over three-quarters of a century.

In 1939, J. Edgar Hoover created a Custodial Detention Index—a secret list of people to be rounded up in a national emergency, assembled without statutory authority and without judicial oversight. In 1943, Attorney General Francis Biddle discovered it and ordered it destroyed, telling the Bureau in writing that there was “no statutory authorization or other present justification for keeping a ‘custodial detention’ list of citizens.”

Hoover disobeyed Biddle’s order, renamed the program the Security Index, and kept it running. It remained secret until after his death, by which point it had grown to more than 20,000 names, nearly all of them American citizens. The renaming was the evasion.

When the Church Committee reconstructed this history in 1976, it found that the FBI’s detention plans were “not only withheld from the public and Congress but were framed in terms which disregarded the legislation enacted by Congress.” The Committee documented that the Bureau “kept secret from the Department”—its own Department of Justice—“its most sweeping list of potentially dangerous persons, first called the ‘Communist Index’ and later renamed the ‘Reserve Index.’”

The names of the systems, and their very existence, were the things held back from overseers, not from criminals. And the lists were not narrow: they swept in labor leaders, journalists critical of the administration, writers critical of the FBI, professors, lawyers, and “other potentially influential persons on a local or national level.” The index system was used to track civil rights and anti-war activists throughout the 1960s and 1970s.

You might be thinking that this is ancient history—Hoover is long dead, and the machinery of oversight built after the Church Committee has fixed the problem. The oversight record since the late 1970s shows both that these systems remain opaque to the people charged with watching them and that the Bureau still turns them against the same categories of Americans.

A first-order question is whether an oversight body can even see inside the entity it is investigating to uncover improper, illegal, or unconstitutional conduct.

The Bureau’s modern investigation case management system, Sentinel, was built only after its predecessor, the Virtual Case File, collapsed in 2005 following roughly $170 million in taxpayer waste. That failure unfolded before the eyes of at least 18 concurrent oversight bodies—including the Government Accountability Office, the DOJ Inspector General, and numerous congressional committees—none of whose published reports identified the root causes before the money was gone.

Saturation-level oversight failed because the system’s actual operation was opaque even to the overseers. That is a warning about competence. What came next is a warning about rights.

When the Inspector General audited Sentinel in 2014 (Report 14–31), it found that the system lacked a basic control to detect and mitigate the insider threat risk posed by persons who access files without a need to know. Sentinel also contains a “Prohibited Access” function that walls specified records off from other users. Read those two findings together and the civil liberties threat becomes clear.

An architecture that can hide a file from an overly curious agent can equally hide it from the people entitled to see it—agents assembling exculpatory evidence, DOJ lawyers responding to a congressional subpoena, FOIA officers processing a request like Cato’s.

A records management system that permits records to be made invisible to its own overseers is the Security Index problem rebuilt in software form.

And the problem is not unique to Sentinel.

The DoJ IG has repeatedly found DOJ-component systems with inadequate audit trails and access controls, in which “data owners do not periodically review access authorizations,” even though DOJ’s own Order 2640.2D requires audit trails “sufficient to reconstruct security relevant events.” The capacity to reconstruct who looked at what—the precondition of any accountability—is precisely what these audits keep finding is absent.

The most recent example does not come from 20th-century history but from the Foreign Intelligence Surveillance Court (FISC) just over four years ago.

A declassified April 2022 FISC opinion records that the FBI conducted “in excess of 278,000” non-compliant queries of a Foreign Intelligence Surveillance Act (FISA) Section 702 database of Americans’ communications and warns that compliance problems with the FBI’s querying “have proven to be persistent and widespread” (at 31, 49).

The queries the court describes are almost a point-for-point reprise of the Security Index categories: a June 2020 batch query run against 133 people arrested “in connection with civil unrest and protests” to check for “derogatory information”; queries tied to the January 6 investigation; queries using identifiers for local businesses and mosques; and a single batch query for more than 19,000 donors to a congressional campaign, of which the Justice Department’s own reviewers found only eight had adequate foreign-intelligence justification (at 27–29, 48).

The FISC suggested that if the violations continued, it might have to “substantially limit the number of FBI personnel with access” to the data (at 49). The Privacy and Civil Liberties Oversight Board, in its 2023 report on Section 702, found “little justification” for the close to five million U.S.-person queries the FBI conducted between 2019 and 2022, and a 2026 PCLOB staff report confirms that querying compliance remained a live concern even after the post-2023 reforms.

Whenever the FBI holds a database of information about Americans and enjoys discretion over whether to acknowledge or deny its existence or how it is searched, the documented pattern—confirmed by courts, inspectors general, and a statutory oversight board—is that the discretion gets used against dissenters, journalists, donors, and political figures.

And the same FISC opinion notes that at least one FBI querying system could not even record U.S.-person queries or the justification for them, forcing personnel onto a separate site they frequently failed to use—the identical audit-trail gap auditors keep finding, now confirmed by the very court charged with overseeing the program.

That is the concrete, present-day harm that a rule shielding the names and existence of such databases places beyond public reach. You cannot request oversight of a system you are forbidden to know exists. This is the harm the current legal test does not address.

Exemption 7(E) asks a single question: Would disclosure help criminals evade the law? It has no statutory language to address the countervailing harm—that secret-by-name tracking systems are how the Bureau has repeatedly escaped oversight and accountability via the attorney general, Congress, and the courts.

There is a constitutional dimension that the circumvention test also omits.

A citizen who cannot learn that a system exists cannot invoke FOIA to see his file, cannot seek redress for an unlawful query, and cannot meaningfully petition Congress for reform of a program that is not publicly known. Secrecy at the level of a system’s identity does not merely inconvenience oversight; it effectively forecloses the First Amendment’s petition right and the due-process interest in knowing what the government has done to you, before either can be exercised.

When a court accepts that the name of an FBI database is too sensitive to reveal because an adversary might “target” it, it is—without confronting this history—reauthorizing the informational asymmetry that made the Security Index possible and the 702 violations publicly invisible for years.

Boasberg could have required the FBI to show, database by database, that naming a given system actually reveals a unique, perishable non-public method—the showing Shapiro contemplates and the Bureau never made. That he did not is a failure to apply the lessons of past surveillance abuses, not an inevitability of doctrine.

The fix is a narrower and more honestly written Exemption 7(E): a database’s name and existence are not, standing alone, a “technique,” and an agency that wants to withhold them must demonstrate what unique, perishable non-public method the name would actually expose.

Anything less lets the government keep secret the one category of information—what systems it maintains and what it calls them—whose disclosure is the precondition for every other check on it.

The Church Committee understood that oversight begins with knowing what exists. The Inspector General’s audits and the FISA Court’s opinions confirm, fifty years on, that the FBI’s bureaucratic machinery still resists being seen and is still turned on the government’s critics.

A FOIA exemption meant to protect unique, perishable law enforcement tradecraft should not become the tool that keeps the public from knowing even the names of the systems being run in its name and potentially being used to track their very patterns of life, much less categorize them as de facto enemies of the state.

You May Also Like

Economy News

Stock Market News: UK Forecast and Technical Analysis Today, the UK stock market saw the FTSE 250 increase by 195 points (0.9%) to 21,628,...

Economy News

Stock Market News: UK Forecast and Technical Analysis Today, the UK stock market saw the FTSE 250 increase by 195 points (0.9%) to 21,628,...

Economy News

Stock Market News: UK Forecast and Technical Analysis Today, the UK stock market saw the FTSE 250 increase by 195 points (0.9%) to 21,628,...

Economy News

Stock Market News: UK Forecast and Technical Analysis Today, the UK stock market saw the FTSE 250 increase by 195 points (0.9%) to 21,628,...



Disclaimer: financehightech.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.