Analysis finds 16 smartphone apps, used as alternatives to ankle monitors in the US, allow access to wide swaths of information and are frequently unreliable
Researchers at the University of Washington and Harvard Law School recently published a groundbreaking study analyzing … Source: USENIX Source: USENIX : Electronic Monitoring Smartphone Apps: An Analysis of Risks from Technical, Human-Centered, and Legal Perspectives
Context & Ripple Effects
Electronic monitoring has been quietly migrating from GPS ankle bracelets to ordinary smartphones: Shadowtrack and SmartLink replaced GPS ankle bracelets for states and ICE as early as 2021, and by mid-2022 privacy advocates reported that [[a:980307|SmartLINK alone helped ICE scale its tracked population from under 6,000 to more than 230,000 in three years]].
The new University of Washington and Harvard Law School study, published at USENIX and flagged by the Electronic Frontier Foundation, is the first systematic audit of that shift: across 16 apps it documents wide-ranging access to user information, embedded third-party trackers, and frequent unreliability — turning years of anecdotal complaints into measured findings.
First-order effects
- The hundreds of thousands of people monitored through these apps — including the expanding ICE caseload built on SmartLINK — now have documented evidence that the software collects broad swaths of their personal data while failing technically, a failure mode parolees on the Guardian app already linked to lost jobs and reincarceration (parolees reported Guardian's technical issues caused job losses and reincarceration).
- The agencies and states contracting these vendors face immediate pressure to justify procurement: the study gives advocates and litigators concrete technical findings about data access and reliability rather than testimony alone.
Second-order effects
- Third-party trackers embedded in government-contracted monitoring apps echo the broader mobile-ad tracking problem documented in free Android apps for a decade (free Android apps secretly connecting to thousands of tracking and ad sites), meaning monitoring vendors may be forced to strip SDKs or defend them as necessary — a governance gap regulators have not yet addressed.
- Vendors like BI Incorporated (SmartLINK) and Shadowtrack now compete on auditability: agencies facing scrutiny over the 230,000-person ICE expansion will demand reliability guarantees and data-access disclosures that raise compliance costs across the market.
Third-order effects
- If carceral surveillance keeps moving onto consumer devices, the structural question shifts from hardware tampering to software governance — who audits what an enforcement app may access, and whether app-store policies or legislation fill the vacuum left by absent procurement standards.
- The pattern mirrors geolocation-harvesting risks already flagged for US intelligence and military personnel's phones (geolocation harvested from common apps risks exposure), suggesting a coming regulatory reckoning over government use of consumer-grade tracking software generally, not just in criminal justice.
The trend: Electronic monitoring is shifting from purpose-built hardware to consumer smartphone apps at a pace that has outstripped any oversight framework for what those apps collect and how reliably they work.