Search
Items tagged with: JoeGebbia
A 2002 federal law,
the E-Government Act,
requires any federal agency that collects personal information through a website to first publish a written privacy impact assessment
explaining what it collects and where the information goes.
The Privacy Act of 1974 requires a separate, parallel public notice,
a “system of records notice”,
describing the records the agency keeps.
A 2010 office of management and budget memorandum extended both requirements to federal agencies’ use of commercial
web-tracking tools, including the kind that PostHog provides.
The Guardian could find no such filings for the studio’s web-tracking layer.
None of the four sites carry a privacy impact assessment naming PostHog or describing the IP addresses and on-site activity the tool collects.
None of the four are covered by a system of records notice that addresses what is collected or where it goes.
The one published privacy instrument that relates to any of the four programmes,
a treasury notice for the Trump Accounts programme,
describes how the children’s-investment programme is administered
but does not name PostHog and does not describe the tracking on trumpaccounts.gov at all.
Davisson, the EPIC attorney,
called the studio’s failure to publish such a notice
“a pretty clearcut violation of section 208” of the E-Government Act,
adding: “There’s just no suggestion that they’re trying to comply in good faith with any of their obligations when it comes to the collection of personal information.”
It’s not known what data was collected from users of the government websites while the tools were live,
whether it was retained
and who has custody of the data.
The use of commercial tools on the sites departs from federal web-team conventions.
Davisson, the senior counsel at the EPIC, described the studio’s work as
“trying to establish their own sort of fly-by-night version of what federal agencies normally do with added tracking technologies
and less oversight”.
This is most apparent in the NDS’s employment of user tracking prior to outreach from the Guardian,
such that when a member of the public visited one of the studio’s federal websites,
a commercial tool called PostHog recorded what they did on the page.
PostHog’s session-recording feature,
which can replay every click, scroll and keystroke of a visitor’s time on a webpage,
is installed in the code of all four sites and enabled on two of them.
On the remaining two, the recording is held inactive only by a single setting inside PostHog’s dashboard,
which can be changed by whoever controls the website at any time.
The Guardian emailed PostHog for comment on its apparent provision of tracking tools to the NDS, but received no response.
Adblockers and similar privacy tools are used by millions of people to limit what third parties can learn about them as they browse.
Most of them work by intercepting requests that a visitor’s browser makes to known tracking services
– and blocking them before any data leaves the device.
Website source code shows that PostHog has been configured on
NDS-run sites to route analytics requests through an address on the federal website itself,
rather than through PostHog’s own servers.
Because the request appears to go to the site the user is already visiting, rather than to a recognisable third-party address, adblockers don’t flag it.
As PostHog explains in its own documentation,
this works “because ad blockers haven’t visited your domain to catalog your setup.
They don’t know what to block.”
In other words, the technique is specifically designed to evade privacy tools
– by presenting commercial tracking as ordinary website activity.
Serge Egelman, research director of the Usable Security and Privacy Group at the International Computer Science Institute (ICSI), explained:
“The issue there is that over the last several years,
due to abuses relating to this type of data collection,
there’s basically an arms race with tools being released to allow consumers to try and exert some control over what data gets collected.”
Egelman said that he had not looked specifically at the PostHog tool or its deployment on federal websites,
but he did point to a lawsuit involving the addition of commercial tracking technology to a state government website.
“I testified on Meta where the [Meta] Pixel was put on the California DMV website.
And Meta was able to obtain information about when people are requesting, say, disability placards,
reinstating a suspended license, things like that
– sensitive information that’s actually protected by federal law.”
He added: “It’s not like someone going to the DMV website expects a private company to receive their personal data and then be allowed to use that however they want.”
PostHog comes with a separate feature called session recording,
which plays back every click, scroll and keystroke a visitor makes,
like a video recording of their entire visit.
Princeton University researchers who first documented the technology in 2017 wrote that watching such a recording was “as if someone is looking over your shoulder”.
On the Trump Accounts and TrumpRX websites, the feature has been built into the page code and is held inactive only by a single setting inside PostHog’s dashboard.
The NDS can turn it on at any time, on either site, without making changes in the underlying website code.
Separately, until the Guardian sought comment on this reporting, the NDS’s own website, ndstudio.gov,
ran a 539-line piece of bespoke code that recorded visitors’ clicks, form entries and navigation;
assigned each visitor a session identifier;
and forwarded the captured data to an address that does not appear anywhere on the public internet.
The script’s source code refers to it as AutoMonitor.
Analysis of the underlying source code for four of the websites written by the secretive National Design Studio (NDS)
found that on at least two of them,
the studio installed a commercial tool called PostHog
that closely tracks what every visitor does on the site.
Another tool, apparently made in-house, sends user data to a destination that is not visible on the public internet.
The NDS apparently removed this tracking software after the Guardian reached out to the White House with a detailed series of questions on the NDS’s operations on 4 June.
On 17 June, White House spokesperson Liz Huston responded:
“All National Design Studio personnel comply with all legal requirements in their important work to improve how citizens interact with their government.”
The studio has also built versions of services legally assigned to other agencies,
including a passports website,
and a copy of
💥Login.gov,
the gateway more than 150 million Americans use to sign in to federal services,
-- the latter reportedly being overseen by a former Doge engineer who moved to the studio.
The NDS has also apparently built a copy of
💥vote.gov,
the federal voter-registration site that by law belongs to an independent bipartisan commission
inside a website site only accessible with a White House login.
🔥A federal voter-registration system run from inside the White House,
with identity and citizenship checks routed through systems the administration controls,
could let an incumbent see who is registering,
or check their registration, in the weeks before an election.
Public ownership records maintained by the Cybersecurity and Infrastructure Security Agency (Cisa)
list the executive office of the president as the registrant of the studio’s sites,
including passports.gov and the vote.gov copy,
👉meaning that the office controls the domains.
Questions remain about the sort of access that this could give the White House to voter registration data.
John Davisson, senior counsel at the Electronic Privacy Information Center (EPIC),
said the studio’s approach risked creating a second version
“a whole sort of second skunk-works version of the federal government
with all these shady tracking technologies
and outside of the parameters of normal federal privacy laws”.
A skunk works is a figurative term for an experimental department within a larger organization with freedom to operate outside normal procedure.
The Guardian sent a detailed list of questions about the NDS to the White House Press Office for the attention of Gebbia and the White House chief of staff, Susie Wiles,
who has oversight of the studio.
Separately, the Guardian sent a request to Gebbia’s presumed email at the NDS
(no addresses are publicly listed).
There was no response.
An opaque White House office staffed largely by veterans of Elon Musk’s
“department of government efficiency”
(Doge) has quietly rebuilt some of the federal government’s most sensitive websites
– for passport applications, voter registration, prescription-drug pricing and children’s savings
– in ways critics say appear to violate federal law.
The National Design Studio (NDS)
was established by a Donald Trump executive order last August,
and is led by Trump-aligned Airbnb co-founder Joe Gebbia and staffed by Doge veterans.
A Guardian investigation has found the office has apparently been developing or redeveloping sensitive federal websites,
including those connecting Americans with prescription drugs, children’s savings accounts, passports and voter registration.
The investigation corroborates and advances earlier reporting by the Drey Dossier, a YouTube investigative outlet.
The NDS built and now operates four public federal websites:
ndstudio.gov,
trumprx.gov,
realfood.gov and
trumpaccounts.gov.
All four ran commercial visitor-tracking software,
configured to evade the privacy tools many web users install,
and none carry the public filings federal privacy law requires under laws including the Privacy Act of 1974 and the E-Government Act of 2002.
Separately, none of the NDS’s spending or its arrangements with outside vendors appears in USAspending,
the federal contracting database,
raising questions about how it is funded and overseen.
Separately, the NDS has also built and runs White House-controlled versions of services the US Congress assigned to other federal agencies,
including a passport-application portal that bypasses the state department’s existing site,
and a copy of voter-registration site vote.gov.
Combined, the sites route sensitive interactions Americans have with their government through infrastructure the White House apparently controls,
and outside the reporting and accountability systems that normally cover federal agencies.
#JoeGebbia #nds #doge #tracking
theguardian.com/us-news/2026/j…
‘It’s dangerous and it’s going to erode trust’: redesign of US government websites stokes surveillance fears
The National Design Studio, staffed by Doge veterans, installed visitor-tracking software on vital federal websitesJason Wilson (The Guardian)
