FLOCK is not an acronym, nor does it represent a set of specific words.  It represents “Flock Safety” — A COLLECTIVE COMMUNITY CONCEPT.

According to Flock Safety, “flock” represents neighbors, businesses, and law enforcement working together as a collective group to protect neighborhoods and reduce crime. Flock Safety manufactures automated license plate readers (ALPR) that capture vehicle details like license plates, make, model, color, and unique identifying marks. This information can be stored anywhere from 7 to 30 days, or even years depending upon which LE agency is doing the collecting. St Petersburg,  and the Pinellas County Sheriff’s Office retention policy is 30 days. A couple of years ago, that number was 2 years. This data is then fed into a centralized database which by design tracks movement and creates a dragnet without a judge’s warrant or individualized suspicion.

What does this mean?  Mass surveillence with no checks and balances. and those entrusted not to abuse the information not only in control of how long the collected data is retained, but also to justify the use by any means necessary.

As Abraham Maslow said, “I suppose it is tempting, if the only tool you have is a hammer, to treat everything were nail.”

ALPR and FLOCK are a tool in the the LE tool belt, but its not the only one.

Data sharing between private communities (like HOA’s) and law enforcement is accomplished through an opt-in model controlled entirely by the private entity. HOA’s and other private communities sign away your privacy and agree to participate. Once a private community opts to share its data, the system links to state and federal law enforcement databases (like the FBI NCIC, etc.) When a vehicle enters or exits a neighborhood, the camera instantly scans the license plate and vehicle attributes (make, model, color, mars). If / when the vehicle matches a “hotlist” profile an automated alert is pushed directly to local police dispatcher sand nearby patrol officers within seconds.  Under U.S. law, a search occurs any time a government agent intrudes upon an individual’s reasonable expectation of privacy. A legal search must be performed by a government employee or LE agent, not a private citizen acting independently and the person must have an actual, subject expectation of privacy that society recognizes as reasonable.

The argument surrounding license plate readers isn’t new in principle. Technology has changed dramatically, but societies have debated the tradeoff between individual liberty and public safety for centuries.

Benjamin Franklin put it memorably in 1755:

“Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety.”

  — Benjamin Franklin

Franklin wasn’t writing about electronic surveillance or privacy databases. His statement came from a dispute involving the Pennsylvania Assembly, taxation and funding for frontier defense.

But the question behind those words remains remarkably relevant.

How much liberty—or, in the modern world, privacy—are we willing to exchange for a false sense of greater security?

And perhaps more importantly, who decides when that exchange has gone too far?

Flock cameras provide a particularly modern version of that centuries-old question. There is legitimate public-safety value in being able to locate a stolen vehicle or identify a car connected to a serious crime, but at what cost?

Providing the capability to capture, search, and warehouse large amounts of data requires building an infrastructure capable of recording enormous numbers of vehicles belonging to people who have done absolutely nothing wrong.

That doesn’t automatically make the technology unacceptable.

It does mean we should be extremely careful about accepting the argument that more surveillance necessarily means more safety.

“In framing a government which is to be administered by men over men, the great difficulty lies in this: you must first enable the government to control the governed; and in the next place oblige it to control itself.”

— James Madison, Federalist No. 51

The Letter of the Law Versus the Spirit of the Law

There is another reason I believe these safeguards deserve scrutiny, and it comes from personal experience.

Over the years, I attended higher education with many people working in law enforcement, and I have also taught law-enforcement professionals. One mindset I encountered often enough to concern me was an intense focus on what could technically be done within the wording of the law, rather than what the law was intended to protect.

The discussions weren’t necessarily about openly violating someone’s rights. They were more often about finding the boundary: How far can an investigation go? Is there another way to obtain the information? Is there a technical distinction that makes evidence admissible? Is there a workaround that accomplishes essentially the same objective?

I’ve even had students whom I had to push away from that way of thinking.

My point to them was simple:

There is a difference between complying with the letter of the law and respecting the spirit of the law.

That distinction becomes enormously important when technology advances faster than legislation.

Our privacy laws were largely developed in a world where tracking someone’s movements required substantial effort. Police might need officers conducting surveillance, investigators following a vehicle, or legal process to obtain certain records.

Technology can eliminate much of that practical barrier. We even have heat signature and power based surveillence that works through walls.

If a database already contains billions of observations documenting where vehicles have been, the question can quickly shift from “Do we have sufficient justification to obtain this information?” to “Is there a legally permissible way for us to access information that already exists?”

Those questions may sound similar.

They aren’t.

And this is why I don’t believe privacy protections surrounding systems like ALPRs should depend entirely upon individual users exercising restraint. I don’t think there is enough controls that could be placed upon the system.

Good information security assumes that eventually someone will push against the boundaries of a system.

Privacy protections should therefore be built into the system itself—not merely written into a policy telling authorized users what they should and shouldn’t do.

Then There Is the Cybersecurity Problem

Once your data is out there, you can’t get it back.

Even if we assume that every law-enforcement agency follows every rule perfectly, every search is legitimate, and every privacy policy is honored exactly as written, there is still another problem:

The data exists.

And once you create a database containing enormous amounts of information about where vehicles have been and when they were there, that database becomes something worth protecting—and potentially something worth stealing.

This is where my concerns as a computer and cybersecurity professional become particularly significant.

There is no such thing as an unhackable database.  One of the earliest and largest publicly recognized database breaches occurred in June 1984. Some of you may know this as the 1984 TRW Credit Data Breach.  Arguably TRW is private company, but government agencies are not immune to database breaches. In fact they are targeted specifically for their high value data. My data was part of the NSA data breach, and over all at least 4 additional times because of governmental databases.

There’s no one stop shop to fix that after it has happened!

Organizations can encrypt information, restrict access, require multi-factor authentication, monitor activity, maintain audit logs, segment networks, patch vulnerabilities and follow excellent security practices. All of those measures can dramatically reduce risk.

They cannot reduce that risk to zero.

Attackers don’t necessarily have to compromise the central database, either. They can target individual agencies, employee accounts, administrative systems, third-party integrations, improperly configured systems, stolen credentials or any other point at which information becomes accessible.

And the more organizations that can access or share a dataset, the larger the potential attack surface becomes.

What Would This Data Be Worth to Someone Else?

Consider what location information could reveal in the wrong hands.

A criminal might want to know when someone’s vehicle normally leaves home.

A stalker or abusive former partner might want to determine where someone regularly goes.

Someone targeting a business owner might want to establish their daily routine.

An attacker could potentially combine vehicle observations with information obtained from social media, public records, previous data breaches and commercially available databases.

That is one of the fundamental lessons of modern cybersecurity:

Information doesn’t have to be sensitive by itself to become sensitive when combined with other information.

A license plate photographed on a public road may seem harmless.

A searchable history containing dates, times and locations associated with that plate is something entirely different.

A Data Breach Can’t Make You “Untracked”

There is also an important difference between compromising a password and compromising historical information.

If someone steals my password, I can change it.

If a credit-card number is compromised, the card can be canceled and replaced.

But I cannot change the fact that my vehicle was at a particular location at a particular time.

Once historical location information has been copied, exported or stolen, deleting the original database doesn’t necessarily retrieve those copies.

That’s why cybersecurity professionals don’t evaluate a system solely by asking whether its information is useful.

We also ask:

What happens if this information falls into the wrong hands?

The usefulness of ALPR data to law enforcement is precisely what can make the same information valuable to someone with malicious intentions.

Collection Creates Responsibility

Every piece of information an organization chooses to collect creates a corresponding responsibility to protect it.

Collect a thousand records, and you have a thousand records to protect.

Collect billions, and you’ve created an extraordinarily valuable information repository.

That doesn’t automatically mean the information should never be collected. But the potential consequences of unauthorized access need to be part of the discussion before the database is created, not after a breach occurs.

This brings us back to one of the most basic principles of information security:

You cannot lose data you never collected.

And you cannot have a massive breach of a database that never existed.


Leave a Reply

Your email address will not be published. Required fields are marked *