Police cameras aren’t just surveilling the road. Nobody can prove who’s watching

krtphotoslive966421-e1790794129335.jpg


Washington spent the last week arguing over Flock Safety. On Sept. 23, a Senate Judiciary subcommittee hearing examined the company’s automated license plate reader network, privacy, misuse, and public-safety value. The next day, Rep. Greg Steube (R-FL) introduced the Facilitating Liberty and Accountability for Flock Observations Act, which would require federal agencies to obtain a warrant before accessing or sharing data from networked ALPR systems.

Those legal and civil liberties questions matter. But they can obscure a narrower issue that does not require choosing between law enforcement and privacy: when a camera network stores searchable records of where vehicles were seen, can the agency using it prove exactly who can reach those records?

That question is newly concrete. Flock says searches are tied to individual users and logged, access is role-based, and most communities use a seven-day retention period unless local rules require otherwise. It has also announced mandatory multi-factor authentication, required case codes for law enforcement searches by year-end, broader audit assistance, and proactive lockout for abnormal behavior. Its trust materials describe those controls.

Security is now an access-control question​


The public safety case should not be caricatured. At the Senate hearing, Pinal County, Arizona, Sheriff Ross Teeple, who had ended his county’s Flock contract, still described ALPRs as useful investigative tools. Sen. Katie Britt (R-AL) likewise argued that law enforcement values and safeguards can both matter. Her office summarized that position after the hearing.

The cybersecurity question begins one layer later: do actual permissions, sharing relationships, and account behavior remain consistent with the written policy over time?

Flock’s own recent security work shows what verifiable assurance can look like. On Sept. 22, the company published a summary of an independent Bishop Fox penetration test covering its hardware, software, mobile applications, and cloud infrastructure. The test identified 36 issues of varying severity. Flock says all critical and high-severity findings were fixed and independently verified, and that none resulted in outside access to customer data or systems. The company published the remediation status here.

That discipline should sound familiar: test a control, expose what fails, remediate it, then verify the fix. Access governance can be judged the same way. A rule saying only approved partners may search data is weaker evidence than a record showing which partners could actually search it, when that permission changed, and what happened when use became unusual.

California shows why configuration history matters​


In February, the Ventura, California, Police Department reported that a vendor-enabled nationwide query function had allowed two out-of-state agencies to query Ventura’s ALPR system during parts of 2025, even though the department believed access was restricted to state partners. Ventura said it had not authorized those queries. Because of limitations in the configuration and logging available at the time, it could not determine whether vehicle data had actually been provided. Ventura published the incident and corrective actions.

Flock separately acknowledged inadvertent out-of-state accessibility in some California networks and said it added safeguards. The lesson is not that every technically possible access became an improper search. It is that configuration history can matter as much as the written access policy.

The San Mateo County, California, Civil Grand Jury made a similar point in August. Reviewing all 17 county law enforcement agencies operating ALPR systems, it found meaningful progress in eliminating out-of-state sharing while identifying remaining gaps in policy maintenance, audits, and oversight of in-state sharing relationships. Its press advisory summarizes the findings.

Salt Typhoon is relevant, but only narrowly​


There is no public evidence that the People’s Republic of China-linked Salt Typhoon campaign accessed Flock systems. Conflating the two would turn a security argument into speculation.

Salt Typhoon matters for a narrower reason. The FBI says PRC-affiliated actors compromised multiple U.S. telecommunications companies and stole call-data logs, a limited number of private communications, and selected information associated with court-ordered law-enforcement requests. Verizon says some mobile internet records reached by the actor included cell-tower locations, times, device identifiers, and destination IP addresses. The FBI’s account is here, and Verizon’s update is here.

A later multinational Cybersecurity and Infrastructure Security Agency advisory described PRC state-sponsored actors using compromised network devices and trusted connections to move through victim environments. That does not establish a bridge to Flock. It establishes a security principle: valuable metadata and trusted relationships deserve scrutiny.

Ask the questions that an incident would force us to answer​


An access-assurance review can remain agnostic on the larger warrant debate. Can an agency list every organization and account that can query its records today? Can it reconstruct when a sharing permission changed and who changed it? Would an administrator know if a trusted partner account began searching at an unusual volume or from an unexpected location? Can outside access be suspended without disabling local searches? Are permission changes and search logs retained long enough to reconstruct an incident?

Flock’s announced case codes, audit assistance, multi-factor authentication, and proactive lockouts move toward those questions. The remaining test is evidentiary: can an agency demonstrate that the access record is complete enough to verify the controls during ordinary use and after something goes wrong?

OPINION: AI ACTS IN SECONDS. TRUMP’S AGENDA HAS AN 84-DAY BLIND SPOT

The most dramatic version of the Flock story imagines a foreign intelligence service secretly watching American roads. The public record does not establish that. The more defensible concern is also more actionable: valuable location data sit behind accounts, permissions, and sharing relationships that can change.

The important question is not whether a camera is watching the road. It is whether the institution responsible for the data can prove who is watching the record.

Burak Oktenli is a graduate student in applied intelligence at Georgetown University and an independent researcher focused on trustworthy artificial intelligence, cybersecurity, autonomous systems, and emerging computing architectures. He holds a bachelor’s degree in computer science and engineering from the University of South Florida and a Master of Business Administration. His work centers on verification, provenance, runtime authority, space governance, and resilient system design for AI-enabled technologies.

Continue reading...

[ H/T Washington Examiner ]

Comments

There are no comments to display
Back
Top