When “Search Everyone” Becomes the Default: What Chatrie v. United States Should Worry Every Engineer

After watching Attorneys for Freedom’s breakdown of the Chatrie v. United States case with digital forensics expert Michele Bush — recorded shortly after oral argument but released the same day the Court finally ruled — I wanted to write down where I land on it, not as a legal analyst, but as someone who builds software for a living and has to think about what our industry’s defaults actually cost people.

If you haven’t watched the video, go do that first. Joey Hamby and Howard Snader walk through the case with Bush in enough technical detail that I’m not going to rehash it point-by-point here. I want to focus on two things: what the geofence warrant actually required Google to do, technically, and just how many people got swept into a bank robbery investigation they had nothing to do with.

The technical shape of the warrant

A 2019 bank robbery in Midlothian, Virginia. Detectives had no suspect, but they knew the robber had a cell phone. So they sent Google a warrant asking for a geofence around the bank — roughly a 300-meter radius, about an hour before and after the robbery.

Here’s the part that should stop any engineer cold: there was no way for Google to answer that request without querying its entire Sensorvault — the location-history database covering, at the time, on the order of 592 million accounts. The warrant wasn’t a request for one person’s records. It was a request for a filter to be run against everyone, with the overwhelming majority of “matches” being immediately discarded as irrelevant.

As Bush explained, a 300-meter geofence sounds tight, but each individual location point in the database carries its own uncertainty radius. A phone with a degraded GPS fix — stuck under tree cover, bouncing off a bad tower — can report a location with a multi-mile margin of error. If that margin of error merely overlaps the 300-meter fence, the account gets pulled into the search.

“Search everyone within three football fields of the bank” quietly became “search everyone whose phone was imprecise enough to maybe have been near the bank.” The geofence is drawn cleanly on a map; the actual dataset being queried is fuzzier and larger than the warrant implies. The issue wasn’t the size of the fence — it’s that determining who is inside or outside that so-called fence is questionable at best.

The numbers

Google’s process, as laid out in the case, queried the full Sensorvault against the geofence and time window, returned an anonymized list — 19 accounts, in this case, identified only by a Google ID (a “GAIA” number), not name or email. The detective then asked Google, informally, for more detail on 9 of those 19 without a new warrant. Then narrowed again, this time asking for 3 to be unmasked with actual identifying information — name, email, phone number. Two of those three were confirmed to have nothing to do with the robbery. The third was Okello Chatrie.

So: one warrant, one search that touched roughly 592 million accounts, in order to identify one suspect, and along the way, unmask two people confirmed innocent — with no additional judicial oversight at the narrowing steps, and with none of the 592 million ever notified that their account had been searched at all.

How they even got to Google

In the video Atty Snader and Ms Bush point out that if the detectives had seized a computer, they would have first gotten a warrant for the computer, then a 2nd warrant to search it, and then a 3rd warrant to go deeper if they found something worth pursuing — each step requiring fresh probable cause before a judge. That’s the general process they describe; the specific technical illustration below is mine, not theirs.

In terms an engineer would recognize: it’s the difference between getting a warrant to grep -l "blah blah" /mnt/suspect-drive and separately getting a warrant to actually open the files that grep turns up. In this particular case, the detectives got one warrant and did the functional equivalent of grep -l "blah blah" /mnt/suspect-drive | xargs cat | tee suspects-record-for-da.txt — searching, opening, and extracting in one pass, without ever getting the intermediate warrant to “mount” the drive and look at what matched. Well, hopefully they thought to air gap the machine; but, I digress.

In the video, Atty Hamby says security footage showed “the bank robber had a cell phone.” He later speculates that’s what pointed detectives to Google in the first place — something in that footage suggesting an Android device.

To take the speculation further, I think the Detectives got lucky that they tried Google first and hit paydirt. Would they have turned around to Apple if they failed there? If that failed, would they have gone to LineageOS? The cell phone provider?

Where I land on it

I agree with Hamby, Snader, and Bush’s framing without much hedging: this is an affront to the Fourth Amendment protections they walk through in the video. The government’s own position — pressed by Justice Gorsuch in oral argument — was that this isn’t a search at all, and that if it needs Google’s cooperation on something else, a warrant isn’t the only tool it has. That should bother you regardless of where you land politically. The mechanism doesn’t care whether the government is looking for a bank robber or someone who showed up at a rally, a church, or a clinic. Once “query everyone, discard the noise” is accepted as not-a-search, the geofence is just a knob the government gets to turn.

That position lost — decisively. On June 29, 2026, the same day this video went up, the Supreme Court ruled 6–3 that acquiring someone’s Google Location History through a geofence warrant is a Fourth Amendment search, full stop. Justice Kagan wrote the majority opinion, joined by Chief Justice Roberts and Justices Sotomayor, Kavanaugh, and Jackson; Justice Jackson also filed a separate concurrence joined by Sotomayor. The Court vacated the Fourth Circuit’s ruling and sent the case back down to work out the messier probable-cause and particularity questions at each step of the warrant — the same step-by-step gap Snader and Bush point to above. Worth noting: Gorsuch, whose questioning of the government’s attorney is the sharpest moment in the oral argument, didn’t actually join the majority — he wrote separately, concurring only in the judgment.

The part that’s on us

Here’s the second thing I want to say, and it’s aimed at people like me — engineers, not lawyers.

It’s easy to watch a case like this and file it under “government overreach” and leave the tech industry’s role in it out of the story. But Google built the Sensorvault. Google built the query tooling that let a single warrant fan out across hundreds of millions of accounts. None of that happened because a court ordered Google to build a mass-surveillance-capable database — it happened because someone, or some team, decided it was worth building, for entirely legitimate product reasons (traffic prediction, “find a coffee shop near me,” and so on). The capability that got compelled into a general search tool was a side effect of good engineering aimed at something else.

Could this have been a case of an over-eager “operator” who wanted to see his/her “query-foo” and was more than happy to answer the detectives’ question? If that’s the case, where’s the DA going “and how do you guys expect me to present this as evidence without my rear-end getting handed to me?” Obviously, there’s a classic Swiss cheese model going on.

That’s the trap I want to name: we build the capability because we can, and we tell ourselves the policy question is somebody else’s job — legal’s, or the government’s, or whoever writes the terms of service. I think that’s a comfortable lie. When you build a system that can answer “which of our 592 million users were within this radius during this hour,” you have built a general-purpose surveillance tool whether or not you intended one, and the fact that it takes a warrant (or, per the government’s own argument here, maybe not even that) to switch it on doesn’t change what you built.

We’ve been here before. Herman Hollerith’s punch-card tabulator was built for the 1890 U.S. Census — an unremarkable data-processing problem — and decades later, licensed into Nazi Germany, it became infrastructure for identifying and tracking populations during the Holocaust (Black, IBM and the Holocaust, 2001). And after Hiroshima, a number of the physicists who’d built the atomic bomb founded the Bulletin of the Atomic Scientists because they felt they couldn’t just walk away from what they’d made — Joseph Rotblat went further and left the Manhattan Project outright in 1944, once it was clear the weapon’s use had outgrown its original justification. I’m not putting a geofence warrant next to either of those in scale or stakes — I only bring them up because the shape of the problem is the same one engineers keep running into: the tool gets built for a defensible reason, and the builders don’t get much say in what it’s pointed at once it exists.

The closest analogue to a geofence warrant, though, and the one worth sitting with longer, is Mark Klein and AT&T’s Room 641A.

Klein wasn’t an executive or a policy-maker — he was an AT&T technician. In 2003, he was assigned to wire optical splitters into AT&T’s San Francisco facility that copied all internet backbone traffic passing through the building and fed it into a secure room the NSA controlled — a room only one specially-cleared employee could enter. Klein’s job was infrastructure, not policy. He just ran the cables. But he recognized what the plumbing implied: this wasn’t a targeted tap on a suspect, it was a full copy of everyone’s traffic, filtered after the fact. He sat on what he knew for over a year, and when a 2005 New York Times story on warrantless NSA surveillance confirmed his suspicion about what he’d built, he came forward with the schematics.

The parallel to Sensorvault is almost exact, just swap “fiber splitter” for “location database.” Room 641A didn’t target anyone up front — it copied everyone’s traffic and let the NSA’s own filtering decide who mattered. The geofence warrant in Chatrie works the same way: it doesn’t target a suspect, it queries everyone and lets Google’s filtering decide who’s a “match.” In both cases, the capability that makes mass collection possible was built for an ordinary, defensible reason — network infrastructure in Klein’s case, useful location features (traffic, navigation, “find a coffee shop near me”) in Google’s — and then repurposed, with the builders potentially being complicit in assuring that what they built wasn’t used for legally, morally, or ethically questionable means.

Klein’s story is also the useful contrast to how Chatrie is playing out: nobody at AT&T or the NSA in 2003 asked whether copying a building’s worth of internet traffic into a black room was something they should build. Klein was the one person in the chain who stopped and asked what the plumbing was actually for — after the fact, admittedly, but he asked. That’s the habit I think our industry needs more of, earlier: not “can we build a system that can answer this query,” but “what happens the day someone points this at everyone instead of just the person we designed it for.”

No wonder the world collectively has a love-hate relationship with Google, Meta, Apple, Amazon, Microsoft, OpenAI, Anthropic, Flock, Uber, Lyft, Tesla and the list goes on.

At some point, we have to be ready to take responsibility for plugging the Swiss cheese hole, and be ready to respond with “with all due respect I’ve been instructed by my lawyer not to say anymore until he/she gets here”.


If you want the full legal and technical breakdown, watch the AOR video — Bush’s explanation of how Google’s query and anonymization pipeline actually works is worth the hour on its own.