Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What we need is a leak of a Flock database. Ideally, due to a security fuck-up by someone other than the jurisdiction that installed them. (Company itself, or another city doing Flock's warrantless search feature.)

Having granular location data for an entire town's license plates should still be creepy and damaging enough that it gets these things torn out and replaced with something more thoughtfully designed.

(Side note: Flock Safety has paid Mercury nearly half a million dollars in lobbying fees [1]. One of the two lobbyists they hired also lobbies for Tencent [2]. The other for Alibaba [3]. In case you're talking to your local, state and/or federal electeds.)

[1] https://www.opensecrets.org/federal-lobbying/clients/lobbyis...

[2] https://www.opensecrets.org/federal-lobbying/lobbyists/summa...

[3] https://www.opensecrets.org/federal-lobbying/lobbyists/summa...



> What we need is a leak of a Flock database. Ideally, due to a security fuck-up by someone other than the jurisdiction that installed them. (Company itself, or another city doing Flock's warrantless search feature.)

With how poor Flock's own security is, using unauthenticated APIs for the vast majority of their service, and camera access points using hardcoded passwords, anyone who's even half motivated could have already done this.


That didn't work for cellular location data, it probably won't work for license plate readers.


> didn't work for cellular location data

The fact that the data would be local is why I suspect the response would be different.


Did I miss a large leak of cellular location data? I would have guessed that would make headlines.


Yeah, historically a lot of the aggregators of cellular location data have had huge security issues.

One of them even had a demo page open to the internet that just had a 'Has consent?" checkbox. Showed me my own location within two blocks without any real validation of consent. No options from the vendor to disable this.

Contacting T-Mobile just gets you a PO Box you can mail a letter to.

An article on one of them from years ago:

https://krebsonsecurity.com/2018/05/tracking-firm-locationsm...


I didn't thank you when I read your source last week. I appreciated it.


> What we need is a leak of a Flock database

In anticipation of this happening someone should build an open source project that processes data points from these cameras, reconstructs movement, correlates the data with with various public and non-public databases, and provides a searchable user interface that will make the average person shit their pants through combination of panic and disgust when they see it.

Then just wait for the inevitable data leak and let the public track the movements of every politician and lobbyist (by name), correlated with their other activities, as well as track anonymized members of the general public.

The average person won't ever "get it" unless they see a system like that for themselves. That might not be enough either but it would lead to some progress if executed well.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: