License plate readers can now track your phone too, thanks to new surveillance tech

Ivan Franco

Posts: 315   +11
Staff member

Imagine that you share a ride to work with the same colleague most mornings. As it passes by a license plate reader, the camera records the car, which can be linked through vehicle records to its registered owner. Beside it, another sensor detects signals broadcast by devices traveling nearby, such as your phone and your colleague's smartwatch.

After enough trips, software may treat some of those devices as a recurring electronic signature associated with the vehicle. Weeks later, one of the same device signals appears alongside a different car connected to an investigation. The signal itself may not contain its owner's name, but its previous association with a known vehicle gives investigators another clue they can use to work out who was carrying the device.

SignalTrace, a system marketed by the security company Leonardo, is designed to work alongside automatic license plate readers. The company says it can recognize groups of consumer devices that regularly move together, then associate them with license plate records and time-stamped locations. The pattern can then be searched even when a police investigator does not know the plate number.

Editor's Note:
Guest author Nicole M. Bennett is a Ph.D. candidate in Geography and Assistant Director at the Center for Refugee Studies at Indiana University. She is a researcher studying the intersection of migration, data governance and digital technologies, with a focus on how AI and algorithmic systems reshape global mobility and humanitarian response. This article is republished from The Conversation under a Creative Commons license.

I am a researcher who studies the intersection of data governance, digital technologies and governments, including surveillance technologies. I see that SignalTrace could further shift how police conduct investigations, putting emphasis on people's movements and associations before their identities are known.

SignalTrace is a tested and marketed capability, but not yet an established police practice. One report indicates that several of the devices are installed in Oxon Hill, Maryland, and the company's predecessor technology appears on an official New York state contract price list.

A narrow definition of identification

Leonardo's new explanatory sheet states that SignalTrace "does not identify people." It says the system "only collects electronic signatures" from signals already being broadcast, such as Bluetooth or radio frequency identification tags. Those signatures, by themselves, do not disclose a person's identity. The company says the output must be corroborated through ordinary investigative methods.

That description relies on a narrow meaning of identity, however. A sensor may not pull a legal name from a phone, but police could still work out who likely owns the device by linking its signal to other records. For example, the same signal might repeatedly appear with a car registered to one person, outside that person's home, or alongside another device already connected to a known subject. That means a person could become part of an investigation because of where their device repeatedly appeared and who it appeared near, even if the police had no reason to suspect that person at the outset.

Leonardo's SignalTrace product page says the system stores electronic fingerprints for later queries and can recognize a vehicle without seeing its license plate. A separate product sheet says the technology helps identify suspects through the mix of devices they carry. The patent behind the system describes targets that may be people or vehicles. It also describes searchable signatures that can be correlated with visual identifiers and used to track a target across locations.

SignalTrace may begin with a nameless pattern, but its value comes from recognizing that pattern again and connecting it to information that police already possess. Once an officer links a recurring signature to a license plate record or case file, the absence of a name in the original signal offers little protection.

A nameless identifier can still be personal

Federal privacy guidance does not limit identifying information to names. The National Institute of Standards and Technology defines personally identifiable information as data that can distinguish or trace a person's identity, either alone or when combined with linkable information. The key question is whether data can single someone out and follow them over time.

Research on mobility data – records collected from people's mobile devices indicating where they went – helps explain the risk. A study in the journal Scientific Reports examined 15 months of records covering 1.5 million people. Four time-and-place points were enough to uniquely identify 95% of the people in the dataset. The study did not test SignalTrace, but it shows why repeated movement can make a supposedly anonymous record distinctive.

The Supreme Court has recognized that phone location records can reveal far more than movement. In Carpenter v. United States, the court concluded that people have a reasonable expectation of privacy in the record of their physical movements.

The court extended that reasoning in its June 2026 decision in Chatrie v. United States. Police investigating a bank robbery had used a type of warrant to obtain anonymized location records for phones near the bank, narrowed the list based on their movements and eventually obtained the names of several users. The justices held that obtaining location data constituted a Fourth Amendment search. It also noted that even short-term monitoring can reveal political, family and other associations.

The ruling does not determine whether police collection of wireless signals detected by SignalTrace would also count as a search. The Chatrie case involved location records, while SignalTrace is designed to detect signals broadcast from nearby devices. But the two technologies raise a related question: What Fourth Amendment protections apply when police begin with unidentified devices and use their movements to determine who might be connected to an event or another person?

Your devices – and the devices of people near you – emit unique electronic signals.

When proximity becomes an investigative lead

The deeper issue is association. A recurring cluster may reflect a family routine or shared commute. It may also capture fellow protesters or passengers who happen to travel together. The system simply observes when people are near one another – it cannot know why people were close to each other.

A device can be borrowed or left in a car. A roadside sensor could capture someone standing nearby. Even a correct match between a device and a vehicle does not establish who carried it on a particular day.

Still, a pattern can direct police attention. Leonardo says SignalTrace is designed to develop leads. Leads influence which records officers request and whose movements receive further scrutiny. By the time an investigator attaches a name, the inferred association has already shaped the inquiry.

A study in the journal Proceedings of the National Academy of Sciences illustrates the power of relational inference. Researchers followed 94 participants using phones that recorded Bluetooth proximity and calling patterns. They found that patterns of behavior could accurately classify 95% of reciprocally reported friendships, with proximity outside work and during off-hours playing an important role in distinguishing friends from other people who regularly encountered one another.

SignalTrace uses a different method, and no independent study has shown comparable performance. The research nonetheless demonstrates that repeated proximity can reveal social ties.

This matters at a protest, for example. A person might come to police attention because their device repeatedly appeared near a group under investigation. The inference would arise from the company they kept, rather than an act attributed to that person.

When anonymous signals become identifying

What SignalTrace shows is a broader change in surveillance practice. Investigators may no longer need to begin with a known person or vehicle. Instead, they can begin with recurring patterns of movement and proximity, then use other records to identify the people connected to them.

That distinction matters because an electronic signature can become identifying without containing a name. A phone detected beside the same devices over time may reveal a relationship before the police know who owns it.

SignalTrace therefore raises a question that existing rules for license plate readers do not fully answer: How should the law treat systems that identify people indirectly through patterns and associations that their devices create?

Masthead image: Scott Webb

Permalink to story:

 
“The company says the output must be corroborated through ordinary investigative methods.”

I understand it’s all the hype right now to be paranoid about license plate readers.. but let’s not forget that your phone can be traced real-time, at any given point, authorized by a warrant you don’t know exists yet… and that’s been the case for many years now. And everyone has a phone on them, almost all of the time.

If you’re going to die on a hill, the “omg they can read my plate legally.. again” hill is probably a silly one to pick.
 
“The company says the output must be corroborated through ordinary investigative methods.”

I understand it’s all the hype right now to be paranoid about license plate readers.. but let’s not forget that your phone can be traced real-time, at any given point, authorized by a warrant you don’t know exists yet… and that’s been the case for many years now. And everyone has a phone on them, almost all of the time.

If you’re going to die on a hill, the “omg they can read my plate legally.. again” hill is probably a silly one to pick.
My hill would be having plates at all. I mean at least with a phone you have the option of leaving it at home, turning it off while driving, or placing it in a faraday bag. Meanwhile you get pulled over if you obscure your mandated automotive ID tag. Personally I see there being a big difference between being allowed to monitor things going on in public (which I am generally fine with) and actively requiring people to do specific things to make themselves easily identifiable.
 
My hill would be having plates at all. I mean at least with a phone you have the option of leaving it at home, turning it off while driving, or placing it in a faraday bag. Meanwhile you get pulled over if you obscure your mandated automotive ID tag. Personally I see there being a big difference between being allowed to monitor things going on in public (which I am generally fine with) and actively requiring people to do specific things to make themselves easily identifiable.
You want to drive, you have to have a license, insurance, and visible registration. Dont like it? Take the bus.

Yes, when you are driving a multi ton steel death machine, you need to have ID clearly visible so when you hit someone, we can figure out who did it. The public, who funded the road system with their taxes, decided on that over 100 years ago.
“The company says the output must be corroborated through ordinary investigative methods.”

I understand it’s all the hype right now to be paranoid about license plate readers.. but let’s not forget that your phone can be traced real-time, at any given point, authorized by a warrant you don’t know exists yet… and that’s been the case for many years now. And everyone has a phone on them, almost all of the time.

If you’re going to die on a hill, the “omg they can read my plate legally.. again” hill is probably a silly one to pick.
Being connected to a cell tower doesnt get someone auto-flagged as being involved in an unrelated crime.

Flock cameras, OTOH.....
 
Last edited:
“The company says the output must be corroborated through ordinary investigative methods.”

I understand it’s all the hype right now to be paranoid about license plate readers.. but let’s not forget that your phone can be traced real-time, at any given point, authorized by a warrant you don’t know exists yet… and that’s been the case for many years now. And everyone has a phone on them, almost all of the time.

If you’re going to die on a hill, the “omg they can read my plate legally.. again” hill is probably a silly one to pick.
The whole issue is the does NOT need a warrant.

They aren’t tracking you they are “just” tracking every device near anything or anyone they suspect. They can later use that association to justify a warrant. Resulting in total warrantless surveillance while still claiming to respect your rights.

If you are truly innocent - just never go near any areas a crime happens or anyone that might do a crime or has gone near a crime themselves - including victims.
 
Def : Communism
Communism’ is an economic and political system, not a catch all word for every government technology you don’t like. If you want to criticize this, criticize the actual issue...privacy, data retention, abuse, and warrant standards.

OT:
I’m actually torn on this one, which probably means it’s a better surveillance story than most.

License plate readers already have a legitimate public safety use. Stolen cars, wanted suspects, missing people, Amber Alerts…fine. I have no problem with technology helping police find people they have an actual reason to be looking for.

But once the system starts saying, “We saw this plate here, and these wireless device signatures were traveling with it, and one of those devices later appeared over there,” we’ve quietly upgraded from license plate reader to relationship mapper with a camera attached.

And before someone yells “COMMUNISM!” from the back row, no. That word does not mean “technology I find creepy.”

The real questions are much less dramatic and much more important....

Who can search the data?
How long is it kept?
Does every search get logged?
Do officers need an actual investigative reason?
What happens when somebody uses it to track an ex, neighbor, journalist, political opponent, or just someone they’re curious about?

Because “we don’t know whose phone it is” is comforting right up until the same anonymous device spends six months appearing beside the same car, house, workplace and grocery store.

Useful technology? Absolutely.

Technology that deserves strict safeguards before we casually build a nationwide cars, phones, locations and associations database?

Also absolutely.

There. I’ve probably managed to annoy both the “nothing to hide” crowd and the “every camera is literally 1984” crowd in one post.
 
Back