Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects.
A joint investigation by 404 Media and WIRED, based on data recovered from a physically removed Flock camera, found that its on-device software explicitly detects people as well as vehicles, bicycles, and license plates.
Separately, Washington DC’s police union says the Metropolitan Police Department used Flock data to track officers under Internal Affairs investigation without their knowledge.
Together, these reports illustrate a privacy problem: A network built to record the movements of vehicles can readily be used to follow almost anyone.
The latest reporting adds an important technical detail to that debate.
What Flock cameras collect
A group of hackers reportedly removed a Flock camera from a roadway, copied its storage, and recovered an encryption key stored on the device. That allowed them to unlock videos of thousands of vehicle detections despite Flock’s claim that its devices are protected by on-device encryption. Flock said it could not assess the claims without more detail.
The recovered camera files reportedly contained software models that detect people, even though public discussion of Flock has usually focused on cars and license plates. The researchers found no evidence that face-recognition features were actively used. Reassuring, but it should not be mistaken for a clean privacy bill of health.
Even without facial recognition, a system that records repeated sightings can potentially reveal sensitive patterns of movement, including where someone lives, works, worships, seeks healthcare, attends protests, visits family, or spends time with other people. When a person is matched to a vehicle, vehicle-based tracking can become person-based tracking in practice.
As an example of how widely the data can be shared, WIRED found that records from the city of Alpharetta, Georgia:
“were accessible to more than 2,000 agencies, including police departments, colleges, airports, and, inexplicably, the Office of Inspector General for the federal General Services Administration.”
Targeted tracking of people
The Washington DC dispute shows what happens when the power to follow people is turned inward.
The DC Police Union says it learned in July that MPD’s Internal Affairs investigators had used Flock license-plate-reader data to track sworn officers under investigation without their knowledge. The union filed a complaint and asked the department to stop, arguing that MPD lacked adequate controls for a system with such extensive surveillance capabilities.
MPD defended the use, saying its position is that the use of license-plate-reader data in the misconduct investigation was appropriate. It said the labor dispute is headed to arbitration.
If police officers themselves are concerned that the system can be used to monitor them without transparent rules, the public should ask an obvious follow-up question: What prevents the same tools from being used to follow residents, employees, journalists, activists, former partners, or other people with no meaningful ability to challenge the search?
Even when Flock wants privacy to meet surveillance halfway, its measures do not eliminate the underlying civil-liberties issue.
The recovered camera software and the DC dispute make the same point from different directions. Flock’s network is not merely a collection of roadside plate readers. It is a distributed system for recording movement, identifying patterns, and making those records available for search.
Meaningful safeguards should include:
- Public approval before cameras are deployed, with clear maps showing their locations and stated purposes.
- Strict limits on collection, retention, searches, and cross-jurisdictional sharing.
- A requirement for documented investigative justification before a search, with elevated approval for sensitive investigations.
- Independently reviewable audit logs, regular public transparency reports, and meaningful penalties for misuse.
- Clear bans on searches related to protected activity, immigration enforcement where local law forbids cooperation, abortion-related investigations, political surveillance, and personal purposes.
- Independent security assessments covering the cameras, cloud services, identity controls, key management, and third-party integrations.
- Automatic deletion that cannot be overridden merely because data could someday be useful.
Privacy cannot depend on authorized users always following rules, vendors configuring every setting correctly, or abuses being discovered the hard way. The first safeguard should be limiting the system’s ability to build a searchable record of ordinary people’s lives at all.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
