What the Actual Flock?
This post is not about sheep, nor even a flock of seagulls or wah wahs for you musically inclined folks. No, this post is about cameras, be they Flock or otherwise.
First it was speed-trap cameras in work zones. Then red light cameras at intersections and speed-trap cameras wherever. Now it is just plain tracking cameras everywhere, apparently accessible anywhere.
If you're a faithful reader of this little slice of 2002, you know I'm not a fan of the surveillance state, and especially the privatization of the surveillance state. I'm all for cameras, but I really appreciate the segmentation of MY cameras on my property from your cameras on your property.
Interestingly enough, the courts are starting to identify that there's a difference between the lack of expectation of privacy in public and the idea that you can be legally tracked by the government throughout your activities. That idea being essentially an incidental lack of privacy vs. searching your activities as a routine practice. We'll see how that plays out in future legal action, but even the Roberts court seems to get privacy things right once in a while. After all, the question about privacy isn't "what do you have to hide," but "why is it your business anyway?"
So let's dive in to the current state and see what is currently happening, what it means to privacy and search, and what we may want to do about it.
Flock Safety: the Kleenex of Automated License Plate Readers
Just as Kleenex is technically just a single brand of facial tissue, Flock is just a single provider of ALPR systems, but when most of us use their name we are talking about the whole raft of them. After all, ALPR isn't catchy, just as facial tissue isn't. But Flock is the best known name for a significant reason: they've got the largest market share and best name recognition. According to my friendly neighborhood AI, here are the top companies in this space in the US:
| Company | Primary Deployment Style | Top Use Case |
|---|---|---|
| Flock Safety | Fixed solar-powered poles | Neighborhoods, HOAs, local police |
| Motorola (Vigilant) | Fixed & vehicle-mounted | Major metros, enterprise law enforcement |
| Axon | Fleet vehicle & dash cameras | Integrated public safety ecosystems |
| Rekor Systems | Software-only / Cloud edge | Highways, transit, smart cities |
| Genetec (AutoVu) | Fixed & mobile hybrid | Transit hubs, universities, parking |
Undoubtedly there are others, and undoubtedly painting the entire industry with a broad brush is not going to be completely accurate. However, trends are trends, commonalities are commonalities. We can absolutely make generalizations about this industry that are, well, generally correct. And we will. But don't mistake that for being spot on accurate about how each organization behaves, there is room for at least some of them to be better than the generalizations we will make in this article. Let's dive in shall we?
The Cases FOR ALPRs
There is absolutely a case for these things. That case is pretty obvious in the abstract: cars are the #1 transport choice for people doing nefarious things. You don't really hear of a lot of "bicycle-by-shootings," kidnappers taking the train, or bank robbers escaping by bus. In an ideal world, these could play a very important role in catching more perpetrators, and catching them faster. This is certainly a laudable and important goal for societies that haven't found a meaningful way to reduce crime rates through other means - which suggests that perhaps they're still just a band-aid approach to an epidemic, but that's a whole other conversation that we'll just walk away from now.
That case assumes some things that don't seem to have translated to the real world however, and those are the things we'll focus on in a bit, however there is this one issue that needs to be addressed: it turns out that the evidence doesn't show that this sort of surveillance is doing nothing to improve solving crimes either more quickly or more often.
There is a secondary case as well - and that is the automation of running a license plate as part of a traffic stop. This case is merely the automation of a process that would take place anyway, where an officer would decide they intend to pull a car over and run the license plate before approaching via his computer. An ALPR would shorten that process and alert the responding officer to potential dangers associated with that vehicle faster. Given that police officers around the country generally seem to agree that traffic stops are the one of their most dangerous duties, this makes sense.
However this use case turns out to be ripe for misuse as well it seems, in our imperfect world.
Top Issues With ALPRs In General
I warned you there would be generalizations. Well, here they are. Buckle up.
Data Aggregation Across Multiple Jurisdictions
Generally speaking, a law enforcement body has a limited jurisdiction for their activities: a town's police are restricted to the town's boundaries, county sheriffs are bound to their county, and state police only work their state, etc. However these ALPRs are private companies contracted by these jurisdictions and they are legally free to aggregate the data about your license plate across anywhere they have a camera.
It has come to light recently that at least one of these ALPR organizations can aggregate the data across multiple jurisdictions to create heat maps of where your vehicle is likely to be at any time of day given the pattern of what cameras it has passed and which ones it has not.
Then there's the question of where the cameras are placed: a camera right outside certain businesses could have a significant negative impact on that location's sales. For example, would you choose to visit the cannabis dispensary with the camera that can see right into its driveway, or would you perhaps head across town to one that doesn't have one of these cameras staring at it? Feel free to replace the idea of a cannabis dispensary with any other place you'd like to consider, from a gentlemen's club to a women's health clinic.
Permissive (or non-existent) Access Control Policies
We've all heard, read, or watched a story about how "bad apple" law enforcement officer used the town's ALPR system to stalk their ex. Or their current significant other. Or somebody famous.
Well, it seems to get worse. Credible reporting states that a LEO several states over may have unfettered access to the ALPR data from a far away city, without any real controls to ensure they're following up on an appropriate investigation and have their paperwork in order.
Mind you, this isn't about calling out police for acting badly. A percentage of any population will misbehave. What this is about is the fact that the proper controls aren't in place to prevent that misbehavior, and they really should be.
Then there's what the security testing/hacking community is finding out about some of these ALPRs. (TLDR, they're less secure than the code for the lock on Dark Helmet's luggage! I'll wait if you have to look that one up) Accessible USB ports, reset buttons that cause the device to stand up a local wifi hotspot, no passwords? Come on, we're decades beyond that level of negligence. And yes, I call it negligence.
Inadequate Legal Protections For ALPR Tracking Data
You would be right in remembering that the Constitution has some pretty good protections in it for us citizens with regard to what our government may do to track us.
However the Constitution is mute on the subject of what private companies may do to track us.
We already know all about data brokers buying and selling everything we do online to anyone who wants to mine it for details about us. We also know that companies are trying everything they can think of to combat our tracking blockers in our browsers - including some admittedly creative ideas. We've been warned about what our phones are tracking about us as well. And let's not forget that Comcast is using their wifi routers like radar systems to figure out if you're home, and calling it a feature.

But let's now add in the idea that the tracking of your car is being added to that pool of data. So now anybody with enough money can have data about your physical whereabouts added to all that info about what you buy, what you search online...I'm not trying to freak you out, but I'm also not going to let you stick your head in the sand either - this stuff is absolutely Orwellian.
No Visibility Into or Control Over Our Own Data
Again, federal law has failed us. Unless your state has some pretty strict laws about what companies can do with PII - and if an IP address can be considered as personally identifiable information (which it is in some jurisdictions) it's a slam dunk to say a license plate is - you have no way of knowing what these ALPR companies are doing with your data. None. There is no transparency.
Oh sure, you can probably submit an FOIA request to your local police department for a copy of the contract between them and their ALPR, and you'll get something back, but it might say that your data can't be used for something specific. But of course that only matters when your data is collected in your town. Now you have to go repeat your FOIA for the other towns you drive through, to, in, or around.
How long do they keep the data? Who do they share it with? Who do they sell it to? What analysis and modeling do they do with it? Has it ever been breached? Has it ever been misused by one of their employees?
So it's one thing that we can't stop them from using our data, but it turns out we don't even have the legal right to demand to know what they're doing with it. That is, in fact, illegal in many parts of the world, just not here in the US.
Leaving Flock for Another ALPR Isn't the Answer
In recent days there have been stories about cities and towns leaving Flock in droves. This is having enough of an impact on Flock's income that Flock has suddenly announced a raft of "privacy" improvements aimed at better controls around abuse of the system by LEOs - not a whiff about improving the security or transparency of the system overall. And they're not likely to unless the financial situation gets even worse for them.
What isn't being shared nearly as widely is that many if not most of them are signing contracts with one of Flock's peers. Peers that haven't gotten the public attention that Flock has. Companies that could be better, but could be worse as well. Without more transparency we'll never know.
But that doesn't do anything to better control the data Flock already has. Petabytes is my guess, given that they have over 100,000 cameras deployed according to published reports, many of them for years and years of 24x7 monitoring and reporting. If Flock finds that their revenues from the cameras themselves are dropping, how might you assume they'll try to monetize what they already have to make up for that loss of income?
The Answer Is Federal Legislation
I know, I just make you roll your eyes. Some of you may have bashed your head on your desk - at least figuratively. For others of you, please take a moment and grab a Kleenex before you continue.
At the heart of this is a technology that - if deployed and used properly - could actually provide value to our society. But at the moment our laws are so permissive for what private companies can do with our data that we live in what I can only describe as a dystopian surveillance state, outsourced to big business. I see the following as the bare minimum for resolving the current issue:
- A GDPR-like privacy and personal data law for the United States. We already have laws (Amendments in the Bill of Rights, in fact) that explicitly provide some level of privacy from the government. But we're left to a patchwork of laws across the states that don't allow for a cohesive solution, and frankly make enforcement ridiculous.
- An overhaul of how data brokers are allowed to work. Opting in as a condition of doing business is coercive - if I can't get my cell phone turned on without agreeing to let my provider share my payment details with a credit bureau then I have no choice in the matter because I need my cell phone in today's society.
- Heightened privacy, transparency, and limiting requirements for companies who collect data from and for law enforcement. The sort of data collected by them should be subject to the same controls as those placed on the government itself as they're acting as an agent of the government in these cases.
Do I expect these three concepts to become law soon? No, not really, But I do know that these are on my agenda as I choose who to elect. I hope they will be for you too.