Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects.
A joint investigation by 404 Media and WIRED, based on data recovered from a physically removed Flock camera, found that its on-device software explicitly detects people as well as vehicles, bicycles, and license plates.
Separately, Washington DC’s police union says the Metropolitan Police Department used Flock data to track officers under Internal Affairs investigation without their knowledge.
Together, these reports illustrate a privacy problem: A network built to record the movements of vehicles can readily be used to follow almost anyone.
The latest reporting adds an important technical detail to that debate.
What Flock cameras collect
A group of hackers reportedly removed a Flock camera from a roadway, copied its storage, and recovered an encryption key stored on the device. That allowed them to unlock videos of thousands of vehicle detections despite Flock’s claim that its devices are protected by on-device encryption. Flock said it could not assess the claims without more detail.
The recovered camera files reportedly contained software models that detect people, even though public discussion of Flock has usually focused on cars and license plates. The researchers found no evidence that face-recognition features were actively used. Reassuring, but it should not be mistaken for a clean privacy bill of health.
Even without facial recognition, a system that records repeated sightings can potentially reveal sensitive patterns of movement, including where someone lives, works, worships, seeks healthcare, attends protests, visits family, or spends time with other people. When a person is matched to a vehicle, vehicle-based tracking can become person-based tracking in practice.
As an example of how widely the data can be shared, WIRED found that records from the city of Alpharetta, Georgia:
“were accessible to more than 2,000 agencies, including police departments, colleges, airports, and, inexplicably, the Office of Inspector General for the federal General Services Administration.”
Targeted tracking of people
The Washington DC dispute shows what happens when the power to follow people is turned inward.
Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects.
A joint investigation by 404 Media and WIRED, based on data recovered from a physically removed Flock camera, found that its on-device software explicitly detects people as well as vehicles, bicycles, and license plates.
Separately, Washington DC’s police union says the Metropolitan Police Department used Flock data to track officers under Internal Affairs investigation without their knowledge.
Together, these reports illustrate a privacy problem: A network built to record the movements of vehicles can readily be used to follow almost anyone.
The latest reporting adds an important technical detail to that debate.
What Flock cameras collect
A group of hackers reportedly removed a Flock camera from a roadway, copied its storage, and recovered an encryption key stored on the device. That allowed them to unlock videos of thousands of vehicle detections despite Flock’s claim that its devices are protected by on-device encryption. Flock said it could not assess the claims without more detail.
The recovered camera files reportedly contained software models that detect people, even though public discussion of Flock has usually focused on cars and license plates. The researchers found no evidence that face-recognition features were actively used. Reassuring, but it should not be mistaken for a clean privacy bill of health.
Even without facial recognition, a system that records repeated sightings can potentially reveal sensitive patterns of movement, including where someone lives, works, worships, seeks healthcare, attends protests, visits family.