back
397 comments
It frustrates me when people call them license plate readers. I guess you need to call them something, but they are general-purpose internet connected cameras. They will do whatever their firmware tells them to do, and could be reprogrammed at any time by anyone with access. No one expected doorbell cameras to join a mass surveillance network, but later the manufacturers added that feature. Why do we treat these cameras like they can do only one thing?
> Why do we treat these cameras like they can do only one thing?

Because its useful messaging to disarm the populace. "License plate reader" sounds less alarming than "Internet connected camera" or "Mass surveillance device."

Public attitudes vary around a "license plate reader" but will be more uniformly opposed to "Widespread, automated government mass surveillance tracking your every move via camera in real time"

> No one expected doorbell cameras to join a mass surveillance network, but later the manufacturers added that feature.

Plenty of people did? That was obviously one of the end goals for cloud connected devices pushing recordings to a remote side for processing and storage. Especially when stuff like facial recognition was implemented server side.

I would be highly surprised if this was not pitched in the first internal product meeting.

While I give some grace to the regular population on this topic - anyone posting on HN should have trivially seen this outcome as not only likely, but nearly written in stone. Even if all your imagination captured was “secret NSA warrant” it would be one of the first risks you’d imagine for such a product.

It was obvious that this was the final outcome even back when Facebook first implemented tagging friends in photos before image recognition got cheap and good enough to go back and time and correlate the social graphs of everyone.

Especially considering Flock's API will give you people not just license plates.

The flag for whether the object/person is law enforcement vs not is interesting as well.

Love that, very cool for quickly filtering out the streams / geodata that might have an officer's actions recorded.

https://docs.flocksafety.com/developer-hub/docs/tracking-obj...

This amounts to an argument against ever using general purpose computing devices to accomplish anything.

You could say the same about literally any privately operated device. ‘I don’t know why they call these things cell towers. They do whatever they are programmed to and can be reprogrammed by anyone with access’

Heck the same applies to non electronic things too ‘why do they call it a house? It’s a general purpose structure and could be turned into a shop or a factory or a crack den at any time by anyone with access’

> No one expected doorbell cameras to join a mass surveillance network

No one? There's a reason I never bought one of these things. This was a pretty obvious outcome to anyone who even slightly distrusts corporations or the government.

"Autonomous dragnet surveillance cameras" wasn't as popular with the focus groups.

> No one expected doorbell cameras to join a mass surveillance network

Doorbell cameras were at least for individual security, initially. There's no attempt being made to market Flock as anything but mass surveillance. Surely we all expect them or their successors to be detecting peoples' faces, walking gates, and who-knows-what-else in the near future.

By that logic, should private citizens need a background check to buy a computer, since a computer could be programmed to run cyber attacks?
I always define them as "Remotely managed, field-upgradeable, multi-interconnected computing devices with full spectrum cameras and other sensory capabilities. Information is monitored in real-time by increasingly capable AI technology. They have edge AI capability for intelligent classification. They can be upgraded without announcement at any time. They can be replaced in the field with higher capabilities at any time. The data they captured can be accessed at any time by anyone with sufficient permissions granted by an entity capable of granting such permissions. Not all users have the same permissions. Multiple user interfaces with differing capabilities exist. There exists a capability to aggregate data streams from multiple sources provided the user has sufficient permissions. Deleted data remains accessible to users with higher clearance."
Don't know if it's true (cuz lazy), but I recently read that they will start tracking phone signals an linking them to plates.
Either it needs a warrant or it’s fully open and people can start creating websites showing the movements of local politicians.

This middle ground that municipalities try to carve out where it’s fully open to police without a warrant but not subject to FOIL laws doesn’t appear tenable for much longer.

There’s been too many cases of police officers stalking exes, poking around the data for fun and such so it’s clear police cannot be trusted with the data without better court oversight.

It’s certainly a very powerful investigative tool, but needs solid 4th amendment protections. The Supreme Court’s recent ruling on geofence searches of cell phone records is a good indication on where the Supreme Court’s head is at on this sort of thing, where they said no you can’t just do blanket data dumps like that without a warrant.

A warrant is better than no warrant, but:

A warrant requirement is not a reasonable bandaid to consider allowing mass spying. There should be no mass spying by default.

A warrant requirement makes sense for something like the locations of customers on cellular networks, because, although it should be improved, it's been built into the tech.

When you make the optional choice to create mass spying, safeguards do not make it acceptable.

Imagine all licence plates being small screens and periodically showing numbers derived from a private key issued by the DMV. As they change, vehicles could not be tracked without knowing the private key, yet the DMV can verify the ownership because they know one. I am not a crypto expert, and the actual scheme may be a bit more sophisticated, but you’ve got the idea.
I don't like the article's tone of inevitability:

> I think cameras in all public spaces are going to happen. Imagine Ring comes out with a nicer camera system for homeowners....

Indiscriminately filming people in public places is illegal some places, e.g. Germany. Allowing the creation of large networks of cameras surveilling public places is a choice.

This is a hole in the Constitution that would be better patched, at least with statute, better with an amendment. The fourth amendment says

  The right of the people to be secure in their persons, houses, papers, and effects...
Who is "their" here? In terms of property rights it's the people who own those digital "papers". The individuals who that data is about do no maintain or control that data, and could not destroy it, meaning they do not functionally have property rights over it. If I write in my notebook that you have blonde hair, the notebook is still my property. There isn't anything I could write about you in it that would make it yours (other than maybe "I hereby give this notebook to Joe Bloe").

Attempts to interpret the Constitution otherwise are, IMHO, attempts at good policy, but unstable as law. So we should fix it either by giving people property rights to that data (so that they can destroy or change it without permission) or to explicitly require warrants for access to PII owned by third parties.

Good article. It's a sober look at where we are at.

We lost a lot of strong privacy rights we had with landlines when we shifted to cell phones.

We're actually slowly creeping into pre-crime territory. You could have AI searching for possible pre-crime candidates based on unknown identity in the area, disparate pattern to usually movements, etc.

You should raise your voices now. For Indians, its too late. Our Indian Government used facial recognition system at mass level in recent students protests and now police is showing up on their homes.

It's better to raise the voice now for you guys than to say sorry later.

There's a fundamental question: Is it legal for the government to blanket a public space in cameras and do whatever they want to the data that they collect from those cameras?

Is it legal for a private entity to do the same with their owned space (like a plaza or mall or office tower)?

Focusing on license-plate-readers seems like car-brain is causing the author to miss the forest for the trees.

Any idea why this is so much less acceptable to people in the US than in the UK? In the UK we've had ANPR for more than twenty years and AFAICT there's no mass controversy surrounding it. It catches people with no licence, no insurance, who are wanted in various serious crimes. I'm surprised at the difference in attitude.

(I am aware that the UK has a less-than-stellar privacy track record... but nonetheless it's curious that for this particular technology, as opposed to the Online Safety Act, there's such a difference.)

A warrant isn't an effective safe guard unless you trust the government to only prosecute actual crimes. The US federal government has demonstrated, explicitly, that it is willing to use law enforcement for political ends and will charge private citizens for political reasons (like the reflecting pool case).

Now is not the time to be giving more power to the executive or its policing functions.

There is another middle option that I would have liked to see the author discuss: requiring either a case number or a CAD ID, instead of a "search reason".

In my conversations with law enforcement (mostly at management level, chiefs of police), all of them have had reasonable-sounding objections to a warrant requirement for a search, but zero of them have been able to come up with a reason why a case-or-CAD ID requirement isn't workable. Generally, they argue that in practice obtaining a warrant can be too onerous in time sensitive situations, and can be harder to obtain than the public realizes. Two popular examples are in kidnappings (time sensitive) and missing persons (difficult to obtain).

A case number or CAD ID however simply requires that the details of either a public call for service or an active investigation are associated with the historical search. It closes the door on officers' hobby searching.

Andrew's blog post does note the problems with oversight, which also match my experience, so this isn't a perfect fix. But it will go further in conversations with law enforcement for people that are trying to thread the needle on making "safe" mass surveillance.

(I am personally opposed to mass surveillance in all its forms, but arguing only from that position pretty much immediately excludes me from policy discussions.)

Here's a case study of what happens when this information is public (it's linked as the "data-driven" series). This information should not exist unless the plate is flagged and the reason for that is sufficient to obtain a warrant. https://www.eff.org/deeplinks/2026/04/open-records-laws-reve...
> Imagine Ring comes out with a nicer camera system for homeowners that has more comprehensive views around your house and is just as cheap. And we will ultimately be safer for it.

I wonder if people who feel this way will feel safer? In this scenario, you have a Ring camera system observing your entire property. Do you feel safer if someone comes onto your property and triggers an alarm? What if it turns out it's just a kid coming over to grab a stray frisbee? What if your neighbor noticed something needed a quick fix (say you left a can of paint open or something similarly benign) and wanted help in a neighborly way without first checking to see if you were home?

I guess we just take for granted that we live in a low-trust society. But we take that for granted at our peril, because the fear of a low-trust society is actively being exploited by people who want to sell individuals, businesses and municipalities the means to further erode that trust.

I do wonder though if the data retention should be restricted at all. This brings up a very good point that even old data (months or more) can be vital to cases or to the defense, but is there any downside to it that would make it worth restricting? And how long?
I am for having it be completely open to the public, or require a warrant. The police should not have special privileges of information lifted directly from the public. Privacy cuts both ways.
Hotlists imply that actual search takes place the moment you pass one, so really, the illegal search happens before. Even if warrants were required to manually search.
They're more than just license plate readers. Much more.
Yeah, because warrants have never been rubber stamped without proper oversight before. If we make these things normalized and routine, they will be abused. Don’t give them an inch.
A judge would never sign off on a warrant for the kind of searches Flock facilitates. Similar opinions involving cell phones have been rejected by the courts multiple times. Folks desperately trying to workshop some line of reasoning by which everyone should apparently be okay with an Orwellian panopticon is pretty annoying.
I agree; however, here is my vibe-coded home ALPRS:

https://github.com/ryjones/alprs

Using more vibe code:

https://github.com/ryjones/platescan

The bar is low.

I think we have the ability to get rid of license plates altogether and restore some privacy. It's not like license plates stop LEOs from shooting people, like when they were chasing Dornier and unloaded on a Blue Toyota Tacoma when they knew his vehicle was a Grey Nissan Titan.
Collecting and storing the information is the real problem. The focus on warrants is a distraction.

Access control (warrant) doesn't prevent a breach, and the system is not architected in a way to prevent internal abuse. The best way to prevent the abuse of data is to not collect or store it at all.

Wire tapping phones requires a warrant, except the chinese hacked into the lawful intercept system. Most Russian government databases are for sale on the dark web. If the data is collected no amount of legal protections will prevent misuse.
Can you poison their database with ai-generated license plates on a screen? Maybe set up a van with a big screen in front of a Flock camera and start generating random license plate numbers?
Monetization of public data for private profit is the heart of my qualms.

Why should it be possible for my bits be scooped up and sold for profit against my will.

There is a concept in safety called the hierarchy of hazard controls. There is a ranking of hazard mitigations from most to least effective.

1) remove the hazard

2) replace the hazard with something less hazardous

3) isolate the hazard (guards, cages etc)

4) administrative controls (procedures, training, warning, etc)

5) PPE

Implementing some kind of judicial review for these panopticons is something like 4) in the hierarchy. It would be a good thing to have, but we can go far further. Why do we need this shit? Oh what so someone’s car doesn’t get stolen a few times per year? I think my values are in line with the founding fathers and most Americans when I say I would gladly give up a little bit of safety to not have a spy camera trained on me 24/7.

I would like more removal and less procedural controls. The cops cannot abuse a system that does not exist.

Makes sense. Interesting to see how the judicial system allows the state to bypass that requirement.
The FISA court is a similar compromise.
Warrants for historical search with warrant-free flags for ongoing issues seems like a nice middle ground. Convincing. Good article.

It seems that would easily impede a lot of abuse and it’s straightforward to believe that historical data is rarely so urgent as to not require a warrant.

A matter of defining historical as a sufficiently old enough thing but that seems feasible.

My jaded opinion is that Flock's mistake was marketing to police departments. In matters of criminal law the accused has these pesky things called "rights". The police have long violated those rights so there are reams upon reams of precedent reinforcing people's rights.

The accused has comparatively no rights when an bureaucrat is shaking them down and the accused is often a business rather than an individual it's easy to have sympathy for. Flock could've run their racket for many years, got much praise from the useful idiots, really gotten their system integrated and entrenched, if they'd have chosen that route.

Their mistake was believing in their own bullshit. They thought they could make it cheaper to solve crimes (at great cost to everyone's rights of course, but they thought this was acceptable) and make things better (or at least their definition of it). If only they had been slightly scummier and instead set out to help municipalities collect civil fines they probably could have gotten away without scrutiny.

Yeaaah for seeing Andy on HN. His stuff is always excellent.
any camera dragnet should be controlled by the local government (not the police department) and all access should require a warrant. end of.
So... should cops require a warrant before reading a plate with thier eyeballs?

There are lots of vids of people claiming that, generally low information sovcits. But it makes for great window smashes.

The best solution is to make your plate readable to humans but not cameras, now how would you do that I won’t reveal much else it will be abused, but think out of the pla.. box, I mean.
A warrant is not required for an AMBER alert, which amounts to poor man's mass surveillance of license plates. We're basically fine with an incredibly intrusive push notification to get people to do the work without hand-wringing about privacy. I think I would rather AMBER alerts take advantage of mass surveillance than require AMBER alerts to get a warrant, but obviously there's lots of nuance to it.
A license plate is already publicly displayed information (and is in most jurisdictions not private property), and you're operating in a public space.

I know it's unpopular but I went from not supporting these sorts of systems to embracing them after seeing the positive effects in China.

For crimes that depend on anonymity, theft, assault, hit-and-runs, vandalism, illegal parking, etc., surveillance changes the calculation because the offender expects a higher or even a near certain chance of being identified/caught in China. I think this is a good thing. I also see no issue with someone breaking the law and receiving a ticket almost immediately.

With all systems, it comes down to the design. What sort of oversight is there, how long is footage stored, can it be used for specific crimes or expanded later, and are there mechanisms to correct false identification.

Done right, these systems work well. I would be happy to live in a society where street crime is rare enough that I can leave personal property anywhere, like a bike, without constantly worrying about theft. I think many fears about these systems come from dystopian science fiction and assume the worst possible implementation, rather than recognizing that technology can be designed with strong safeguards.

funny question I have to pose now because I haven't thought about it yet in all the ALPR discussions and the like.

There are civilian enterprise uses of ALPR. Where do they fall in this? I don't even mean for mass data collection or even for parking enforcement. I'm thinking of like various car washes where they offer monthly memberships and their car wash portal system has plate recognition to tie your membership to your car. Or other enterprise access control applications where the ALPR pops the gates open instead of RFID tags.

let the butter churn! Y'all forget that USNORTHCOM is active and has been operating since 10/1/2002. It is a brave new world. In this post 9/11 world let us not forget that we voted away our right to privacy for the greater good! I for one welcome our robot overlords, how else will we survive?