The Digital Iron Curtain
13 / 22
How Meta, TikTok, X, YouTube, and LinkedIn Silenced Palestine There is a word for what happens when a government controls what its citizens can see, say, and share. We call it censorship, and we have historically associated it with authoritarian regimes — Soviet-era information blackouts, Chinese internet firewalls, North Korean state media. We did not expect to find it operating at the fingertip level of a billion-dollar Silicon Valley algorithm, quietly throttling the voices of besieged people while the bombs fell.
But that is precisely what happened. And it is still happening.
Since October 7, 2023, the most powerful social media platforms on earth — Meta's Instagram and Facebook, TikTok, X (formerly Twitter), YouTube, and LinkedIn — have functioned as a coordinated, if not always consciously coordinated, suppression machine. Journalists have been banned without explanation. Human rights organizations have had their archives erased. Activists documenting civilian deaths have been shadowbanned into invisibility. Evidence of potential war crimes — video, photographs, firsthand testimony — has been deleted from the public record at the request of a foreign government, with a compliance rate that should shock every person who has ever been told these platforms stand for freedom of expression.
They do not. They stand for profit and political protection. This chapter documents what they did — platform by platform — and who paid the price.
Meta: Instagram and Facebook — A Government's Preferred Censor
The scale of Meta's suppression of Palestinian voices during the Gaza genocide is not disputed. It is documented, quantified, and in Meta's own words — admitted.
In December 2023, Human Rights Watch released a landmark 51-page report, Meta's Broken Promises: Systemic Censorship of Palestine Content on Instagram and Facebook, which documented over 1,050 verified cases of content removal and suppression from more than 60 countries between October and November 2023 alone. The pattern was not random. It was systematic: content deleted, accounts suspended without explanation, hashtags rendered unsearchable, Instagram Live features disabled, and the quiet algorithmic throttling known as shadowbanning — reducing the visibility of a post or an account without notifying the person being silenced. Palestinian journalist Ahmed Shihab-Eldin, whose Instagram account had nearly one million followers, lost access to his account five times in the weeks following October 7. He was not alone. (Source: Human Rights Watch, "Meta's Broken Promises," December 2023, https:// http://www.hrw.org/report/2023/12/21/metas-broken-promises/systemic-censorship-palestine-c ontent-instagram-and)
The mechanism Meta used most frequently was its "Dangerous Organizations and Individuals" policy — a broad content moderation framework that incorporates the U.S. government's terrorist designation lists. Because Hamas is on that list and governs Gaza, Meta's automated systems flagged and removed content that merely mentioned Hamas in a neutral or
journalistic context. The AI could not distinguish between a reporter documenting a Hamas statement and a person expressing support for violence. It flagged both. According to Human Rights Watch, Meta removed even neutral mentions of Hamas in relation to developments in Gaza. The result was that reporting on the most heavily covered genocide in the world was systematically deleted from two of the most widely used platforms in human history.
What makes this more than a content moderation failure is the role of the Israeli government. According to media reports cited in the Human Rights Watch investigation, Israel's Cyber Unit sent Meta and other platforms approximately 9,500 content takedown requests in the weeks following October 7, 2023 — 60 percent of which went to Meta. Platforms responded with a 94 percent compliance rate. Let that number sit for a moment. When a foreign government sends a list of content it wants removed from an American social media platform, Meta complies 94 percent of the time. According to subsequent reporting, Meta complied with approximately 96 percent of Israeli government removal requests — the highest compliance rate of any country in the world. This is not content moderation. This is a foreign government using an American corporation as a censorship arm, and the corporation accepting the role willingly. (Source: Access Now, "How Meta Censors Palestinian Voices," February 2024, https://www.accessnow.org/publication/how-meta-censors-palestinian-voices/; World Socialist Web Site, December 2023, https:// http://www.wsws.org/en/articles/2023/12/22/rrys-d22.html)
Meta's own translation algorithm added the word "terrorist" to the bios of Palestinian Instagram users — automatically, without their knowledge or consent — in October and November 2023. When this was discovered and reported, Meta called it a bug. An error. A technical malfunction. The same explanation it has offered, and continues to offer, every single time its systems are caught doing something that happens to benefit one side of a genocide.
This was not Meta's first offense and they knew it. A 2021 independent report commissioned by Meta itself — conducted by Business for Social Responsibility — found that the company's content moderation "appear[s] to have had an adverse human rights impact on the rights of Palestinian users," adversely affecting their ability to document and share their experiences. Meta agreed to make changes. Almost two years later, Human Rights Watch found that those changes had not been implemented. The "broken promises" of the report's title referred not to a surprise failure, but to a documented pattern of commitment and non-delivery. (Source: Human Rights Watch, https://www.hrw.org/news/2023/12/20/meta-systemic-censorship-palestine-content)
TikTok: The Platform They Tried to Ban for Showing Too Much Truth
TikTok's story in the Gaza genocide is different from Meta's — and in some ways more revealing about how power operates in Silicon Valley and Washington, D.C.
Unlike Instagram and Facebook, TikTok did not emerge as a primary suppressor of Palestinian content. The data pointed in the opposite direction. A Washington Post analysis in November 2023 found that the hashtag #freepalestine appeared on TikTok 38 times more often than #standwithisrael — a ratio comparable to what the same study found on Meta's own platforms. The Arab Center for Social Media found that for every pro-Israel post on TikTok, there were approximately 54 pro-Palestine posts. Palestinian journalists and documentarians — including Emmy Award-winning filmmaker and journalist Bisan Owda, whose videos beginning with "It's Bisan from Gaza, and I'm still alive" reached audiences that mainstream Western media
was not reaching — found in TikTok a distribution channel that had not yet been captured by the forces seeking to control the narrative. (Source: Washington Post, "TikTok Disables Hashtag View Counts After Gaza War Controversy," February 2024, https://www.washingtonpost.com/ technology/2024/02/08/tiktok-remove-data-criticism-gaza/)
The response from Washington was immediate. By October and November 2023, Republican senators including Josh Hawley and Marco Rubio were explicitly citing TikTok's Gaza coverage as a reason to ban the app. Representative Mike Gallagher, who spearheaded the TikTok divestiture legislation, argued in a public op-ed that the app was responsible for turning young Americans against Israel. The legislation passed. The Chinese parent company ByteDance was told to sell or be banned. The proposed buyer of TikTok's U.S. operations was Oracle — the same Oracle providing database infrastructure to the Israeli military's intelligence apparatus, as documented in Chapter Two. (Source: The Intercept, "The TikTok Ban Is Also About Hiding Pro-Palestinian Content," January 2025, https://theintercept.com/2025/01/09/tiktok-ban-israel-palestine-republicans/)
When TikTok was briefly banned for U.S. users in January 2025, one of its most prominent Palestinian journalists, Bisan Owda, was permanently suspended by the platform shortly afterward — without warning, without explanation, in what she described as "political pressure linked to Israel." Her account, which had documented the human cost of the Gaza genocide in real time to millions of viewers, was gone. The pro-Palestine news outlet Mondoweiss had its TikTok account permanently banned without warning during an earlier surge in Israeli military operations. TikTok, meanwhile, reported that it had removed 4.7 million videos and suspended 300,000 livestreams between October 7, 2023 and September 15, 2024 — invoking its policies against promoting Hamas, hate speech, or misinformation. The question of how those policies were applied, and to whose content, is one the platform has never answered in public with any transparency. (Source: Middle East Online, "US Ownership of TikTok Leads to Bans on Palestinian Influencers," January 2026, https://middle-east-online.com/en/us-ownership-tiktok-leads-bans-palestinian-influencers-journal ists; Euronews, October 2024, https:// http://www.euronews.com/next/2024/10/07/human-rights-ngos-say-social-media-platforms-cont inue-to-censor-pro-palestine-content)
What TikTok reveals is not primarily a story of the platform suppressing Palestinian content — it is a story of a platform being legislated out of existence precisely because it was not suppressing it. When a social media platform allows the truth to be seen, Washington intervenes. That is the lesson of TikTok and Gaza. And it is a lesson worth understanding clearly before moving on.
X / Twitter: The "Free Speech" Platform That Silenced Palestine
Elon Musk purchased Twitter in 2022 with a stated commitment to free speech absolutism. He positioned himself as the liberator of a platform he claimed had been strangled by liberal censorship. He reinstated banned accounts. He fired the trust and safety teams. He replaced professional fact-checkers with a crowdsourced system called Community Notes that functions, in the words of his own critics, as the digital equivalent of leaving a complaint in an unmonitored suggestion box.
What Musk's "free speech" platform actually produced, where Palestinian content was concerned, was a selective application of silence. In October 2023, X suspended hundreds of Palestinian accounts, describing them as affiliated with Hamas, without providing evidence for individual determinations or a meaningful appeals process. Among those suspended in January 2024 were prominent journalists and commentators whose accounts were removed without warning and without stated cause — including senior staff writer Alan MacLeod of Mint Press News, Intercept reporter Ken Klippenstein with over 500,000 followers, and a cluster of other left-wing and pro-Palestinian journalists and activists. Their accounts were restored hours later. No explanation was provided. No rule that had been violated was named. (Source: Al Jazeera, "Twitter Under Fire for Censoring Palestinian Public Figures," February 2023, https://www.aljazeera.com/features/2023/2/28/twitter-under-fire-for-censuring-palestinian-public- figures; World Socialist Web Site, January 2024, https://www.wsws.org/en/articles/2024/01/10/doux-j10.html)
While Palestinian voices were being throttled, a November 2023 report by the Centre for Countering Digital Hate found that X was failing to moderate 96 percent of hate speech posts related to the Israeli genocide in Palestine— including posts describing Palestinians as animals, calling for collective punishment, and inciting violence against civilians. The same platform that suspended hundreds of Palestinian accounts for alleged Hamas affiliation was leaving anti-Palestinian incitement online at a rate of 96 percent. This is not an inconsistency. It is a policy. The digital rights organization 7amleh documented more than 19,000 cases of hate speech and inciting content in Hebrew on X in the weeks following October 7 — content that remained online without consequence. (Source: Business and Human Rights Centre, "Report Exposes X's Failure to Remove 96% of Hate Speech Posts," November 2023, https://www.business-humanrights.org/en/latest-news/report-exposes-xs-failure-to-remove-96-of -hate-speech-posts-amid-israel-palestine-conflict/)
On Christmas Eve 2023, Instagram — not X — permanently terminated the account of activist Shaun King, who had been documenting Israeli war crimes to a massive audience. On X, actress Susan Sarandon posted a photograph of billboards calling for a ceasefire. It was flagged as "violent speech." The billboard said: Stop the Bombs. This is what free speech absolutism looks like when it is built and operated by a man who has publicly declared that empathy is civilization's fundamental weakness.
YouTube: Erasing the Evidence
YouTube's role in the suppression of Palestinian content has two distinct phases. The first is a years-long pattern of algorithmic discrimination against Arabic-language content from the West Bank and Gaza — documented in research by 7amleh, Al-Shabaka, and Article 19 well before October 2023. The second is more recent, more direct, and more damning: YouTube's deletion, at the request of the Trump administration, of over 700 videos documenting Israeli human rights violations.
The earlier pattern is important context. Research conducted by 7amleh and reported by Al-Shabaka found that YouTube's AI content moderation systems applied what researchers called "locative discrimination" — flagging content at higher rates based on the geographic origin of the upload. Videos from the West Bank and Gaza faced a higher level of automated scrutiny than equivalent content from elsewhere. Arabic-language content was flagged disproportionately
compared to Hebrew-language content of equal sensitivity. Palestinian journalists who challenged these removals received no explanation from YouTube — and no meaningful appeal pathway. The platform's AI had rendered a verdict, and there was no court of appeal. (Source: Al-Shabaka, "YouTube's Violation of Palestinian Digital Rights," https://al-shabaka.org/briefs/youtubes-violation-of-palestinian-digital-rights-what-needs-to-be-do ne/)
Then, in October 2025, YouTube quietly erased the accounts of three of Palestine's most important human rights organizations: Al-Haq, the Al Mezan Center for Human Rights, and the Palestinian Centre for Human Rights — the oldest human rights organization in Gaza, as designated by the United Nations. Gone with those accounts were over 700 videos: investigations into Israeli strikes on civilians, testimonies from survivors, a documentary about mothers surviving the genocide in Gaza, and a filmed investigation into the killing of Palestinian-American journalist Shireen Abu Akleh. The content was not removed because it was violent. The content was not removed because it violated community guidelines. It was removed because the United States government sanctioned these organizations for cooperating with the International Criminal Court's investigation into Israeli officials.
YouTube confirmed to The Intercept that the deletions were made to comply with U.S. sanctions. Katherine Gallagher, a senior attorney at the Center for Constitutional Rights, called it "outrageous that YouTube is furthering the Trump administration's agenda to remove evidence of human rights violations and war crimes from public view." Sarah Leah Whitson of Democracy for the Arab World Now described it as "a disappointing act of submission." The Palestinian Centre for Human Rights said plainly that YouTube's actions "shield perpetrators from accountability." (Source: The Intercept, "YouTube Quietly Erased More Than 700 Videos Documenting Israeli Human Rights Violations," November 2025, https://theintercept.com/2025/11/04/youtube-google-israel-palestine-human-rights-censorship/; Common Dreams, https://www.commondreams.org/news/youtube-deletes-videos-israel)
Let me be direct about what this means. YouTube — a subsidiary of Google, which holds a $1.2 billion cloud contract with the Israeli military through Project Nimbus — deleted evidence of potential war crimes committed by the Israeli military, at the request of a U.S. administration that has shielded Israel from accountability at the International Criminal Court. This is not a content moderation decision. This is corporate complicity in the erasure of a historical record. It is the digital equivalent of burning documents before the trial.
LinkedIn: The Professional Network That Watches You
LinkedIn presents itself as the respectable face of Silicon Valley — the platform for résumés and thought leadership, for career milestones and industry networking. It is owned by Microsoft, whose cloud infrastructure, as documented in Chapter Two, is embedded in the Israeli military's operational systems. And in April 2026, LinkedIn became the subject of a class action lawsuit and a sweeping investigative report that exposed one of the most comprehensive covert surveillance operations in corporate history.
The investigation — published by a nonprofit research organization called Fairlinked and dubbed "BrowserGate" — revealed that every time a user visits linkedin.com on a Chrome-based browser, a hidden JavaScript program silently scans their device for installed browser extensions. The program runs without any visible indicator, requests no consent, and discloses nothing. It
reports its findings — a precise fingerprint of the user's browser environment — directly to LinkedIn's servers. The scale of the operation has grown dramatically: LinkedIn scanned for 38 specific extensions in 2017. By 2024, that number had grown to 461. By February 2026, it had reached 6,167 — a 1,252 percent increase in two years. A class action lawsuit was filed in the U.S. District Court for the Northern District of California on April 7, 2026, accusing LinkedIn of running a "covert surveillance system" embedded in its own website. (Source: CyberInsider, "LinkedIn Faces Class Action Over Alleged Covert Scanning of Users' Browsers," April 2026, https://cyberinsider.com/linkedin-faces-class-action-over-alleged-covert-scanning-of-users-brow sers/; Cybernews, https://cybernews.com/privacy/linkedin-lawsuits-illegal-browser-extension-tracking/)
The significance of this surveillance goes beyond privacy violation for its own sake. The Fairlinked report argues — and the class action complaint alleges — that the data collected through this browser scanning is precise enough to allow LinkedIn to infer sensitive attributes about users: political affiliations, religious beliefs, health conditions, union membership, and ideological orientation. The fingerprint persists across cookie resets. In an era when pro-Palestinian advocacy has been classified by some governments as grounds for employment discrimination, immigration screening, and even criminal investigation, a professional network that can silently identify your political leanings from your browser profile is not a neutral tool. It is a surveillance instrument embedded in the professional infrastructure of over one billion people worldwide. In October 2024, the Irish Data Protection Commission fined LinkedIn €310 million for processing users' personal data for targeted advertising without a valid legal basis — the largest fine ever issued to LinkedIn under Europe's GDPR framework. The BrowserGate revelations suggest the problem runs deeper than advertising. (Source: The Next Web, "LinkedIn BrowserGate: Extension Scanning, Privacy, Fingerprint," April 2026, https://thenextweb.com/ news/linkedin-browsergate-extension-scanning-privacy-fingerprint; SecurityWeek, https:// http://www.securityweek.com/browsergate-claims-of-linkedin-spying-clash-with-security-resear ch-findings/)
LinkedIn has denied that it uses the scanned data to infer sensitive information about users. It says the scanning is a security measure to detect tools that violate its terms of service by scraping data without consent. That is a plausible explanation for scanning dozens of known scraping tools. It is not a plausible explanation for scanning 6,167 browser extensions — including extensions for personal productivity, health tracking, political research, and religious community organizing. At some point, a security measure becomes a surveillance infrastructure. The lawsuit will determine which category LinkedIn's behavior falls into. What is not in dispute is that the scanning happened, that users were not informed, that no consent was sought, and that the data went to LinkedIn's servers. For a platform owned by Microsoft — a company whose cloud systems are documented tools of military targeting — the question of what that data is ultimately used for is not paranoia. It is the right question to ask.
"The War on Maps — How Big Tech Erases a People Before the Bombs Fall"
There is a form of violence that happens before the first airstrike. Before the first checkpoint. Before the first home is demolished. It happens on a screen, at a zoom level, in the quiet political
decisions of engineers and product managers who decide which places deserve a name on a map — and which places do not.
I want to talk about maps.
Because if you have been paying attention to what is happening in Lebanon — if you pulled up Apple Maps during the Israeli bombardment of April 2026 and looked at the southern part of the country — you saw something that stopped people cold. Most of it was blank. The villages were not labeled. The towns that had existed for centuries, that families had been ordered to evacuate under threat of bombardment, simply did not appear. Meanwhile, on the same app, small Israeli communities across the border — Nahariyya, Shelomi, Beit Jan — were clearly labeled, their names sitting on the map as if the landscape itself had taken a side. (Source: The New Arab, "Did Apple Erase Lebanese Village Names from Its Maps?," April 2026, https://www.newarab.com/news/did-apple-erase-lebanese-village-names-its-maps)
Apple's explanation — that these Lebanese villages were never in the application to begin with, that the detailed version of Apple Maps has not yet completed its global rollout in Lebanon — may be technically true. Multiple fact-checkers confirmed that archived user complaints about Lebanon's sparse Apple Maps coverage go back to 2019, years before any of this began. I am not making the claim that Apple removed villages in real time as Israeli bombs fell, because the evidence does not support that specific claim.
What I am saying is something more disturbing.
The villages were never in the maps. And the Israeli communities across the border always were.
That disparity did not begin in April 2026. It was not created by the current aggression. It is the baseline. It is the default. It is what these applications look like on an ordinary day, when no one is paying attention and no one is comparing screenshots side by side and no one is asking why places that have been inhabited for centuries simply do not appear on the most widely used navigation tool in the history of humanity.
That is not a technical limitation. That is a political choice that compounds, over years, into something that looks like erasure — because it is.
Google Maps and the Map That Never Said Palestine
Let me be specific, because specificity is what separates documentation from accusation.
Google Maps has never labeled Palestine as a state. Not once since the service launched in 2005. The West Bank and the Gaza Strip appear as geographic regions with no national designation, while Israel is fully labeled as a country with Jerusalem identified as its capital. This is despite the fact that Jerusalem's status is a final-status issue in every international framework resolution, where the UN General Assembly in 1947 granted Jerusalem international status under Resolution 181, and the International Court of Justice has been explicit that Israeli sovereignty over East Jerusalem is not recognized under international law.
Settlements appear labeled as if they were inside Israel. They are not. They are illegal under Article 49 of the Fourth Geneva Convention, which prohibits an occupying power from transferring its civilian population into occupied territory. But on Google Maps they appear as communities like any other — with clearly visible names, calculated routes, measured distances — while the Palestinian villages of Area C of the West Bank, land that has been farmed and
inhabited for generations, only appear when you zoom in so far that you have already passed them by.
Then there is the matter of routing. 7amleh, the Arab Center for the Advancement of Social Media, published a detailed report examining Google Maps' navigation decisions in the occupied territories. When a Palestinian in the West Bank tries to navigate from Bethlehem to Ramallah — a journey of 36 kilometers — Google Maps routes them through Jerusalem. Which most Palestinians cannot legally enter. Palestinian residents of Gaza and the West Bank carry green ID cards that restrict their movement. They cannot use Israeli-only roads. They cannot cross into Jerusalem without a permit that most of them do not have. Google Maps, built on the most sophisticated geospatial data in human history, cannot find a route. It directs people onto roads where they will be arrested for using them. (Source: +972 Magazine, "Lost in Occupation: How Google Maps Is Erasing Palestine," https://www.972mag.com/mapping-occupation-how-google-erases-palestine-from-its-maps/)
The Kyl-Bingaman Amendment — a U.S. law passed in 1997 — restricts the resolution of satellite imagery that American companies can provide of Israel and the occupied Palestinian territories. The high-resolution imagery that is freely available for every other country in the Middle East is deliberately degraded over Israel-Palestine. Researchers trying to document the destruction of villages, settlement construction, and evidence of possible war crimes have lower photographic resolution to work with in this particular conflict than they would have when analyzing any comparable situation anywhere else in the region. This is not a technological accident. It is a law passed by the United States Congress specifically to protect one country's ability to act without photographic scrutiny. (Source: Al-Shabaka, "Maps, Technology, and Decolonial Spatial Practices in Palestine," https://al-shabaka.org/briefs/maps-technology-and-decolonial-spatial-practices-in-palestine/)
In August 2016, Google's maps removed the labels "West Bank" and "Gaza Strip" entirely. Not the territories themselves, just their names. They disappeared from the map as if the geographic designations that everyone uses to refer to these places simply no longer existed. More than 615,000 people signed a petition: "Google: Put Palestine on your maps." Google called it a bug. It restored the labels. It said nothing more. (Source: +972 Magazine, ibid.)
A bug. The most sophisticated mapping company on the planet — a company that sends cars down every road in every country, that has mapped the ocean floor, that can tell you a restaurant's opening hours in Reykjavik — accidentally deleted the only geographic labels that acknowledged the existence of Palestinian territory.
I want you to compare that explanation with what you know about these companies. These are not organizations that make careless mistakes about the geography of disputed territories. They are organizations with entire teams of policy specialists, government liaison offices, legal departments, and geopolitical risk consultants whose job is precisely to manage decisions like these. Every labeling choice in Google Maps is a political decision. Every routing algorithm reflects implicit assumptions about who is allowed to go where. Every omission of a Palestinian village is a decision not to show it: a choice made, reviewed, and approved by human beings in offices in Mountain View and Cupertino who understood what they were choosing.
What a map does before the bombs fall
There is a reason militaries have always prioritized cartographic erasure. A place with no name on a map is harder to defend under international law. It is harder to report from. It is harder to mourn. When a journalist files a story about an airstrike and the location does not appear on any of the major mapping apps, the story becomes harder to situate — harder to verify — and harder to visualize for a public that navigates the world through apps built by American tech companies.
In southern Lebanon, during the April 2026 bombardment, Israel ordered hundreds of thousands of people to evacuate villages that did not appear on the maps most of the world was using to follow the news. The blank space on the map was not the cause of the bombing. But it was complicit in the invisibility of those who were bombed. When you cannot find a place, it is harder to mourn the people who lived there.
I am not going to let tech companies hide behind the word "bug." I am not going to let them hide behind "global rollout timelines" while one side of a border is blank and the other is fully labeled. I have been in this industry for thirty years. I know how to tell the difference between a technical limitation and a political decision dressed up in technical language. And so do they.
The map is not neutral. It has never been neutral. The question is: whose reality does it reflect — and whose does it erase?
Sign the petition at NoEthicsInBigTech.com. Demand that Google label Palestine as a state in accordance with UN General Assembly Resolution 67/19, which recognized Palestine as a non-member observer state with 138 votes. Demand that illegal Israeli settlements be identified as such, in accordance with all applicable provisions of international law. Demand that routing algorithms take into account the movement restrictions imposed on Palestinians, rather than directing them onto roads where they will be arrested for using them. These are not radical demands. They are requests to reflect reality.
The companies that build the maps we all use have the power to make the occupation visible or invisible. They have chosen, systematically, invisibility.
That choice has consequences. And the people who pay the consequences are not in Mountain View.
The Surveillance Industrial Complex — From Israeli Spyware to the Government Shopping Cart I have spent this chapter documenting how Big Tech platforms silence, censor, and erase the voices of people they have been asked to suppress. But I want to step back from the specific mechanism of censorship and address something more fundamental — because the erasure of speech is only one layer of the surveillance architecture that has been built over the past two decades. Beneath it is something older, more invasive, and more consequential: the infrastructure of watching. In my documentary Forever Peace Now, I documented what the surveillance economy actually looks like from the inside — through the testimony of engineers, civil liberties advocates, congressional staffers, and people who had lived inside the machine long enough to understand what it was doing. What I found, across years of those conversations, was a consistent pattern: the tools built ostensibly to protect us were being used against us. The promises made to sell those tools were false. And the people who knew were not speaking loudly enough for the public to hear. I want to tell you three of those stories here. They are connected. Together, they describe a surveillance infrastructure that no single law governs, that no single company controls,
and that the government has found ways to use without the messy inconvenience of obtaining a warrant.
NSO Group and the Spyware That Murdered a Journalist NSO Group is an Israeli technology company. It builds surveillance tools — specifically a piece of software called Pegasus that is, in the understated language of the cybersecurity community, one of the most invasive tools ever commercially deployed against civilian populations. Pegasus can be installed on a target's smartphone without any action by the user — no link to click, no file to open. It operates silently, invisibly, and comprehensively. Once installed, it can access messages, emails, call logs, photographs, and location data. It can activate the microphone and camera without the user's knowledge. It turns your phone into a surveillance device that reports everything it sees and hears to whoever purchased the access. NSO Group sells Pegasus to governments. Not to individuals, not to corporations — to governments, exclusively, who use it against journalists, activists, lawyers, dissidents, and opposition politicians. The company has always maintained that its tools are only sold to vetted governments for legitimate law enforcement purposes. The record does not support this claim. In October 2018, Jamal Khashoggi — a Saudi Arabian journalist and Washington Post columnist who had been critical of Crown Prince Mohammed bin Salman — entered the Saudi Arabian consulate in Istanbul. He was killed there. His body was dismembered. Investigators subsequently established that Khashoggi's phone had been infected with Pegasus spyware, and that the surveillance data derived from that infection had been used to track him in the period leading up to his murder. A tool sold by an Israeli company to a Gulf monarchy was used to locate, track, and facilitate the assassination of a journalist who worked for an American newspaper. (Source: Citizen Lab, University of Toronto, Pegasus reporting; Washington Post, multiple dates 2018–2019) The United States government placed NSO Group on its Entity List in November 2021 — a designation that restricts American companies from doing business with it — citing that NSO had "developed and supplied spyware to foreign governments that used these tools to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers." Israel, whose government has regulatory authority over NSO Group's export licenses, has continued to allow the company to operate, because the tools it builds serve Israeli intelligence and diplomatic interests as much as they serve the governments that buy them. This is what I described in the film as the surveillance industrial complex — the merging of military-grade intelligence capabilities with commercial business models and government relationships, deployed against civilian populations worldwide. NSO Group is the most visible node of that complex. It is not the only one. It is simply the one whose tools were used to kill someone whose name you know. The Israeli technology sector — whose graduates from Unit 8200 of the Israeli Intelligence Corps flow directly into both Silicon Valley and Israeli defense tech startups, as I documented in Chapter Two — is the world's largest exporter of commercial surveillance technology per capita. Blue Wolf and Red Wolf, which I described in Chapter Two as the biometric occupation systems deployed against Palestinians in the West Bank, are products of the same ecosystem. The Gospel and Lavender targeting systems are products of the same ecosystem. And the clients for this surveillance technology are not limited to democracies with independent judiciaries and free press. They include governments whose record on human rights is well documented and whose use of these tools against their own citizens is not hypothetical.
The United States government, which placed NSO Group on the Entity List, has simultaneously continued to operate in partnership with the broader Israeli surveillance technology ecosystem through Project Nimbus, through Unit 8200 alumni's presence across Silicon Valley, and through the intelligence-sharing arrangements of the Five Eyes network. The condemnation of NSO Group and the embrace of the infrastructure that produced it are not contradictions. They are different applications of the same technology, serving different political masters.
Apple's Privacy Theater and the Promise That Was Never True Apple has built its brand on privacy. "What happens on your iPhone stays on your iPhone." The tagline is on billboards. It is in television commercials. It is in the keynote addresses that Tim Cook delivers with the measured cadence of a man who has decided that privacy is a product differentiator and is prepared to treat it as one. I have spent thirty years in the technology industry. I know what a product differentiator is. And I know the difference between a company that treats privacy as a value and a company that treats it as a marketing position. The record on Apple is, at best, complicated. Let me be specific about what I mean. In 2021, Apple announced plans to scan the content of iCloud photo libraries for child sexual abuse material — a goal that is genuinely important and morally urgent. The problem was the mechanism: Apple's proposed system would scan images on users' devices before they were uploaded to iCloud, comparing them against a database of known CSAM hash values. The Electronic Frontier Foundation and a coalition of security researchers and civil liberties organizations responded immediately with a letter signed by over 90 organizations from around the world: the system, however well-intentioned in its initial design, created infrastructure that could be repurposed. A scanning system built to detect one category of illegal content could, under government pressure or corporate policy changes, be expanded to scan for other content — political speech, religious material, journalism. Apple eventually abandoned the proposal, citing concerns from privacy advocates. But the fact that it was proposed at all revealed something important about how Apple thinks about the privacy it markets. In China, Apple has removed apps from its Chinese App Store at the direction of the Chinese government — including VPN apps that allow users to circumvent censorship, including apps used by protesters in Hong Kong during the 2019 demonstrations, including tools used by journalists working in a country where journalism requires protection. Apple has stored Chinese users' iCloud data on servers operated by a Chinese state-owned enterprise called GCBD — meaning that the encryption keys for Chinese users' most private communications and data are held by a company legally required to cooperate with the Chinese government. Apple has complied with Chinese government requests to remove Taiwanese flag emoji from devices operating in China. The privacy that Apple promises its users is, in the Chinese market, explicitly conditional on what the Chinese government is willing to allow. This is not a surprise. Tim Cook has said, with characteristic corporate diplomacy, that Apple believes it can do more good by operating in China than by withdrawing. I do not question the sincerity of that belief. I do question what it means in practice for the users who trust Apple with their most intimate data, believing the promise of the billboard, not knowing that the promise has a geographic boundary that stops at the jurisdictions where it becomes commercially inconvenient to honor it.
The Encryption Lie: How the NSA Paid to Break the Internet In 2004, the National Security Agency made a secret payment of $10 million to RSA Security — at the time one of the most
trusted names in commercial encryption — in exchange for making a specific algorithm the default random number generator in RSA's widely distributed BSAFE cryptographic library. That algorithm was called Dual EC DRBG: Dual Elliptic Curve Deterministic Random Bit Generator. RSA told its customers that it was an approved, secure algorithm. RSA had put their trust in the standards and guidance from NIST — the National Institute of Standards and Technology, the U.S. government body responsible for certifying that encryption standards are what they claim to be. Cryptographers had flagged problems with Dual EC DRBG as early as 2007. The mathematics of the algorithm suggested — to anyone who looked closely — that there might be a secret relationship between two of its key parameters that would allow someone who knew the relationship to predict its outputs. In other words: a backdoor. A way to decrypt communications that the users believed were protected. In 2013, documents released by Edward Snowden confirmed what the mathematics had suggested. The NSA had deliberately inserted the backdoor into Dual EC DRBG, had pushed it through NIST's standardization process to give it the appearance of independent certification, had paid RSA $10 million to make it the default in products used by developers around the world, and had spent $250 million per year through a classified program called Bullrun specifically to insert backdoors into commercial encryption software and hardware. NIST — the agency responsible for telling the world that the standard was secure — had been, in the language of the Snowden documents, "eventually" brought under NSA's control as the sole editor of the standard. (Source: Reuters, "Exclusive: Secret contract tied NSA and security industry pioneer," December 20, 2013, https://www.reuters.com/article/us-usa-security-nsa-rsa/exclusive-secret-contract-tied-nsa-and-s ecurity-industry-pioneer-idUSBRE9BJ1C220131220; New York Times, "N.S.A. Able to Foil Basic Safeguards of Privacy on Web," September 5, 2013; Wikipedia, Dual_EC_DRBG, https://en.wikipedia.org/wiki/Dual_EC_DRBG) Let me translate this into plain language, because the technical framing has allowed it to escape the moral clarity it deserves. The United States government told the world that a specific encryption standard was secure. The government knew it was not secure. The government had secretly made it not secure, on purpose, by paying the most trusted name in commercial encryption to build the backdoor in and deploy it at scale. Developers around the world used that standard in good faith to protect their users' private communications. Those communications were accessible to the NSA. The people whose private data was exposed were never told. The companies whose products contained the backdoor were, by RSA's own account, not informed of the vulnerability at the time they accepted the $10 million. This is not a historical footnote. This is the foundational event in modern surveillance architecture — the moment when it became documented fact that the agency responsible for telling Americans their digital communications were secure was simultaneously the agency secretly ensuring they were not. The companies that told you your data was protected were, in some cases, being paid to make sure it wasn't.
The Government Doesn't Need to Spy Anymore. It Can Just Shop. Here is the part that should stop you cold, because it represents a development more recent and more structurally significant than either Pegasus or the NSA backdoor. The United States government no longer needs to build surveillance infrastructure to watch its citizens. It no longer needs to install spyware on phones, or insert backdoors into encryption standards, or run room-sized data collection operations at AT&T facilities — though all of those things still happen. It does not
need to do any of them, because the surveillance has already been done. It is being done continuously, every day, by the apps on your phone. And the government can simply buy the results. The data broker industry — companies like Venntel, Babel Street, and dozens of others — purchases vast quantities of data from smartphone applications, web browsers, and connected devices. The location data from a fitness tracking app. The browsing history from a news aggregator. The purchase patterns from a retail loyalty program. The political content engagement from a social media platform. All of this is aggregated, cross-referenced, and sold in detailed dossiers that can reveal a person's movements, their health conditions, their political beliefs, their religious practices, their personal relationships, and their daily routines — in many cases with greater precision and completeness than any direct wiretap could achieve. The Department of Homeland Security, the FBI, the IRS, ICE, and the Secret Service have all purchased cell phone location data from data brokers without warrants. DHS signed a $1 billion contract with Palantir to deploy AI-powered data analytics systems across all DHS components — including CBP and ICE — using data purchased through these channels. Government agencies have argued that the Fourth Amendment's requirement for a warrant does not apply when they are purchasing commercially available data rather than compelling its disclosure — a legal distinction that privacy lawyers have called constitutionally indefensible but which courts have not yet definitively resolved. ICE uses tools to track mobile phones and identify devices that have visited specific locations. They have a $30 million contract with Palantir for ImmigrationOS — a platform designed to track people for deportation with near-real-time visibility. The same company whose tools are documented as central to the targeting systems killing civilians in Gaza is also the company building the deportation tracking infrastructure that uses purchased data to find immigrants who have committed no crime beyond their presence. Congress has failed to close this loophole. The Fourth Amendment Is Not For Sale Act passed the House with bipartisan support in 2024 — it would prohibit government agencies from purchasing data they would otherwise need a warrant to obtain — and the Senate never voted on it. The Trump administration has pushed for clean reauthorization of FISA without privacy reforms. The surveillance architecture grows larger. The loophole remains open. What this means in practice is something I have been trying to explain to policymakers, advocates, and anyone who will listen since I produced Forever Peace Now: the surveillance state does not need to surveil anymore. It outsourced the surveillance to the free market. Every app you install, every service you use, every device you carry is doing the surveillance on its behalf. The Fourth Amendment was written to protect you from government intrusion into your private life. It was not written for a world in which your private life is continuously catalogued by private companies and sold to the highest bidder, who happens to be the government. The law has not kept up. The surveillance has. And now, with the AI tools described in Chapter Twelve, the government's ability to process, analyze, and act on purchased data has expanded to a scale that no previous surveillance program could have achieved. Not because the government built better tools. Because it hired the tools from the same companies building the AI systems that everyone uses every day. The AT&T technician who discovered the NSA's secret room — the splitter cabinet in the internet room at 611 Folsom Street in San Francisco, where a glass prism split the laser light beam carrying internet traffic and sent one copy to the NSA — described what he had seen in testimony that appeared in my film. He
found it in 2003, he reported it, and nothing changed. The room is still there. And the room is no longer necessary — because the data flows to the government now through a commercial transaction rather than a secret wire tap, and no whistleblower can easily see the purchase order. The lesson of thirty years in technology, of Snowden and Pegasus and the RSA backdoor and the data broker marketplace, is this: the promise of privacy was never the product. The product was always the data. And the people who told you otherwise — the companies that put "privacy" on billboards, the standards bodies that certified algorithms they knew were compromised, the government agencies that told you they needed the surveillance to protect you — were, in each case, describing something other than what they were actually doing. The most dangerous surveillance state in the world is not China, with its social credit system and its facial recognition cameras. It is the United States — because ours is the only one that has perfected the art of building comprehensive surveillance infrastructure while maintaining, with a straight face and a beautifully designed billboard, that privacy is the product.
Sources: Citizen Lab, University of Toronto, Pegasus spyware research: https://citizenlab.ca/ category/research/ Reuters, "Exclusive: Secret contract tied NSA and security industry pioneer," December 20, 2013: https://www.reuters.com/article/us-usa-security-nsa-rsa/exclusive-secret-contract-tied-nsa-and-s ecurity-industry-pioneer-idUSBRE9BJ1C220131220 Wikipedia, Dual EC DRBG: https://en.wikipedia.org/wiki/Dual_EC_DRBG Brennan Center for Justice, "Closing the Data Broker Loophole," February 2024: https://www.brennancenter.org/our-work/research-reports/closing-data-broker-loophole Electronic Privacy Information Center (EPIC), "Closing the Data Broker Loophole: Government Evasion of the Fourth Amendment": https://epic.org/documents/closing-the-data-broker-loophole-government-evasion-of-the-fourth-a mendment/ NPR, "Your data is everywhere. The government is buying it without a warrant," March 25, 2026: https://www.npr.org/2026/03/25/nx-s1-5752369/ice-surveillance-data-brokers-congress-anthropi c Project on Government Oversight, "Closing the Data Broker Loophole": https://www.pogo.org/fact-sheets/fact-sheet-closing-the-data-broker-loophole Forever Peace Now (documentary film), directed by Vahid Razavi, 2025 — testimony of AT&T technician, Electronic Frontier Foundation, and civil society advocates on surveillance architecture
The Pattern, Named
Taken together, these five platforms form a digital architecture of suppression. Meta deleted over a thousand pieces of Palestinian content in sixty days and complied with 94 percent of Israeli government censorship requests. YouTube erased 700 videos documenting potential war crimes at the direction of the Trump administration. X suspended Palestinian journalists while leaving anti-Palestinian hate speech online at a 96 percent rate. TikTok became the target of a congressional ban explicitly motivated by its failure to suppress Palestinian content. LinkedIn built a covert surveillance system capable of inferring users' political affiliations without their knowledge or consent.
None of these companies will describe what they did as censorship. They will use words like "content moderation," "community guidelines," "sanctions compliance," and "platform integrity." These are the bureaucratic labels of an industry that has perfected the art of doing terrible things with respectable language.
I have interviewed the policy makers who make these decisions. I know what "platform data integrity" means when the quarterly earnings call is next week. It means: we will do what is financially and politically convenient, and we will call it policy.
The Palestinian Observatory of Digital Rights Violations documented more than 1,350 instances of online censorship across major platforms between October 2023 and July 2024 alone. Behind each of those 1,350 numbers is a journalist, an activist, a parent, a survivor — someone who tried to show the world what was happening to them, and was silenced by a company that will report record profits in its next earnings call.
That is the Digital Iron Curtain. It is not maintained by a government. It is maintained by shareholders. The silencing documented in Chapter Nine operates at the level of human decision — a government request, a platform compliance, a post removed. Chapter Ten moves to a more disturbing form of control: the systematic manipulation of what AI systems themselves believe, and therefore what the people who consult those systems are told is true. What governments and their contractors cannot remove from the record, they are now attempting to train out of the machines that compose the record.