A Hacker's Guide to Flock Safety Cameras
What Flock's camera network is, how it works, why it matters for civil liberties, and how to push back without handing anyone a case against you.
What Flock’s camera network is, how it works, why it matters for civil liberties, and how to push back without handing anyone a case against you.
The problem isn’t that a camera can read your license plate. It’s that it’s not just about license plates anymore.
Modern surveillance systems can do things like capture faces, distinguish vehicles without readable plates, analyze movement and potentially gait, record video, correlate people and vehicles across locations, and watch the ordinary places where people live their lives: parks, playgrounds, schools, neighborhoods, clinics, churches, businesses, and protests.
A license plate is just one identifier.
The real problem is that we’re quietly building the infrastructure to make ordinary life searchable.
There are nearly 300,000 Flock cameras in the US, deployed and planned according to FlockSurveillance.org.
They sit on poles at intersections, neighborhood entrances, shopping center lots, and increasingly around the ordinary places people spend their lives: a small black box, usually under a solar panel.
They look temporary because a lot of them are. No trenching, no grid hookup, no fiber. Bolt it to a pole, connect over LTE, and the surveillance starts.
What’s on the pole
Flock’s core product is an automatic license plate reader, but “plate reader” increasingly undersells what the broader system represents.
The camera triggers on motion, not on plates. Each pass gets logged with a timestamp and location, and the software can tag characteristics such as vehicle make, model, color, dents, stickers, roof racks, and other identifying features.
The plate is one searchable field among many.
Even when it can’t read the plate, you can still end up with a record of the car.
And that’s an important distinction.
Identification doesn’t necessarily require a license plate anymore.
A unique vehicle with a particular color, body style, damage, sticker, roof rack, and travel pattern can potentially be interesting even when the plate itself isn’t readable.
String enough observations together and you stop looking at individual photographs.
You start looking at a pattern of life.
And Flock’s ecosystem already extends beyond the traditional ALPR. Its product line includes recorded and live video, third-party camera integration, acoustic detection, and drones.
That’s why the distinction matters.
The public debate started with:
Should police be able to automatically read license plates?
The technology is pushing us toward a much larger question:
How much of ordinary public life should become permanently searchable?
The typical unit has a camera, onboard computing, GPS, a cell modem, a battery, and usually solar charging. Because of that battery, losing external power doesn’t necessarily take a unit offline.
The product line is wider than the flagship camera:
-
Falcon: the familiar fixed LPR camera, with highway and flex variants
-
Condor: live and recorded video, including PTZ
-
Wing: pulls third-party cameras into Flock’s system
-
Raven: acoustic detection for things like gunshots, fireworks, and crashes
-
Drones: expanded through Flock’s acquisition of Aerodome
Flock reduced its recommended/default ALPR retention period from 30 days to seven days in 2026, although actual retention can vary by customer, contract, and applicable law.
That helps.
But retention is only one variable.
Sharing, access controls, audit quality, exports, integrations, and how easily information can migrate into another system matter just as much.
Beyond the camera
Nothing prevents surveillance infrastructure from eventually incorporating other sensors.
Bluetooth, Wi-Fi, toll transponders, and tire-pressure sensors all broadcast identifiers of one kind or another. Modern phones increasingly randomize addresses, but accessories, older devices, and active connections can still leak information.
TPMS is the one people underestimate.
With appropriate radio equipment and signal processing, those transmissions can be detected at distance. Similar techniques have been explored in military, automotive, and drone research.
There are important limits: a TPMS identifier generally doesn’t contain a VIN or announce who owns the vehicle. Someone first has to associate the identifier with a particular vehicle or location.
Once that association exists, though, it becomes another potential tracking token.
And unlike a camera, most people never think about their tires broadcasting anything at all.
The upside is real
It would be dishonest to pretend this technology has no legitimate public-safety value.
It does.
ALPRs can help recover stolen cars, locate missing people, and generate investigative leads after shootings, robberies, and other serious crimes.
Anyone pretending otherwise isn’t being honest.
The problem is that the same infrastructure that can find a stolen Civic can potentially determine who drove to a clinic, church, union meeting, political gathering, gun range, mosque, journalist’s office, or protest.
That’s the uncomfortable bargain.
The technology doesn’t know the difference between finding a stolen car and reconstructing someone’s life.
The people controlling the database decide that.
Flock Misuse
And people have already demonstrated why that matters.
Officers have been accused of using ALPR access to look up exes, spouses, romantic interests, and women they encountered through police work.
In September 2026, five Indianapolis officers were criminally charged over alleged misuse of Flock searches. The Washington Post reported that more than 100 law-enforcement employees nationwide had been accused of abusing ALPR access.
Flock’s CEO has publicly apologized for misuse of the company’s systems.
But individual abuse is only part of the problem.
Sharing is the bigger issue.
WIRED reported that Alpharetta, Georgia shared Flock data with more than 2,000 organizations.
California agencies discovered hundreds of improper searches performed for federal or out-of-state requesters.
Illinois investigated searches connected to immigration enforcement and an attempt to locate a woman who had undergone an abortion.
When one jurisdiction shuts down access, the number of outside organizations suddenly losing access can demonstrate just how interconnected these systems have become.
This fits a broader pattern in modern data infrastructure.
Palantir-style platforms demonstrate what becomes possible when enormous datasets are linked, searched, correlated, and scored.
To be clear: Flock says Palantir has no relationship with it and has no access to Flock customer data. I’m not claiming they’re one system.
That’s not the point.
The point is that once society normalizes collecting enormous amounts of location information, someone will inevitably find value in correlating it.
The right to protest doesn’t mean much if somebody can later produce a searchable list of everyone who showed up.
The Supreme Court has already recognized that a durable record of someone’s movements can reveal dramatically more about their life than any individual trip made in public.
Flock’s security record
Then there’s the security of the surveillance system itself.
The public map at FlockSurveillance.org originated from an unauthenticated endpoint associated with an ArcGIS deployment used by Flock.
That exposure revealed an internal dataset containing hundreds of thousands of existing and planned camera locations.
That’s an important distinction.
This wasn’t somebody wandering around America with binoculars cataloging poles.
The information was available through infrastructure exposed to the internet.
Separately, security researchers Benn Jordan and Jon “GainSec” Gaines discovered more than 60 Condor camera feeds accessible without passwords, including some with PTZ controls and archived footage.
Flock characterized the incident as a limited customer misconfiguration and said the problem was fixed.
Regardless of whose configuration caused it, the result matters:
Cameras deployed to watch the public were themselves publicly watchable.
Multiple independent researchers have now demonstrated security exposures involving infrastructure designed to collect enormous amounts of information about people’s movements.
And systems containing that kind of information are inevitably attractive targets.
Criminal groups want it.
Stalkers want it.
Private investigators want it.
Foreign intelligence services would certainly find it interesting.
Hackers are going to poke at it simply because it’s there.
Flock maintains that it has not suffered a major compromise of its central systems.
There are also APKs and technical artifacts attributed to Flock circulating in the security-research community. Claims based on those artifacts should be treated as research leads unless independently verified.
That distinction matters.
If we’re going to criticize a surveillance company for collecting evidence on everyone else, we should bring receipts when we’re examining them too.
The Halloween Movement
There’s a social-media movement encouraging people to go after Flock cameras on Halloween.
You can see why somebody thought Halloween sounded clever.
Costumes and face coverings are normal. Streets are crowded. People are everywhere.
There’s just one problem.
It’s also an absolutely spectacular night to generate evidence.
Extra patrols.
Doorbell cameras.
Commercial CCTV.
Traffic cameras.
Other ALPRs.
Phones recording everywhere.
Vehicles producing telemetry.
People posting photographs and videos.
And, because the date was announced publicly in advance, investigators already know when to pay attention.
So let’s make something extremely clear:
We are not recommending that anyone damage, disable, remove, access, interfere with, or otherwise fuck with a Flock camera.
Apart from the obvious legal problem, there’s another reason:
Doing it anonymously is considerably harder than people seem to think.
So rather than explaining how somebody might attack one, let’s approach the problem the way a security professional should.
Suppose somebody did interfere with a camera.
How would investigators catch them?
Your phone isn’t the only witness
People tend to imagine digital tracking as one giant glowing dot representing their phone.
Reality is messier.
And worse.
Your phone was somewhere.
Your car was somewhere.
Your smartwatch talked to something.
Your vehicle may have produced telemetry.
Your route may have crossed residential cameras, commercial CCTV, traffic cameras, other ALPR systems, or someone’s doorbell.
Your accounts generated timestamps.
Other people’s devices generated timestamps.
And the damaged camera produced something extremely valuable:
a time and place around which investigators can begin correlating everything else.
Investigators don’t necessarily need one perfect piece of evidence.
Twenty boring pieces of evidence pointing toward the same person can be considerably more useful.
Even disappearing can become evidence
Powering down a phone doesn’t magically erase someone’s digital history.
Carrier records, cloud logs, vehicle telemetry, home cameras, account activity, and historical patterns can still exist.
And suddenly changing an established pattern can itself become interesting.
Imagine a device that generates location and network activity every evening for six months.
Then, on the exact night something happens nearby:
Nothing.
Then it returns.
That doesn’t prove a crime.
But it can create an anomaly worth investigating.
That’s the OpSec lesson people routinely misunderstand:
You don’t become anonymous simply by removing one source of evidence. You may instead become an anomaly inside a system containing dozens of other sources.
Humans are usually the vulnerability
And then humans finish the job.
Someone talks.
Someone screenshots a conversation.
Someone forwards a group message.
Someone posts a photograph.
Someone keeps distinctive clothing.
Someone searches for the camera beforehand.
Someone tells a friend who tells another friend.
Someone makes a joke online three days before a camera mysteriously eats shit.
Someone records what happened because it looked cool.
Someone posts it because getting Internet points seemed more important than not creating evidence.
Attackers spend enormous amounts of time worrying about encryption while carrying the single largest vulnerability in the operation between their ears.
That’s true in ransomware operations.
It’s true in espionage.
It’s true in penetration testing.
And it’s certainly true here.
The camera isn’t necessarily dead
There’s another misconception worth killing:
Taking away external power does not necessarily mean a Flock camera immediately stops operating.
These systems can contain batteries precisely because they’re designed for locations where permanent electrical infrastructure isn’t practical.
So an investigator doesn’t necessarily have to reconstruct what happened entirely from outside sources.
Depending on the equipment, configuration, connectivity, and what occurred, the system itself may still have generated useful telemetry or evidence around the event.
Assuming the thing you’re attacking stopped watching you because you interfered with it is a particularly bad assumption.
And Flock isn’t the only camera
This is probably the largest misconception surrounding anti-surveillance actions.
People focus on the surveillance device they’re protesting.
Meanwhile:
The gas station saw them.
The apartment building saw them.
The Tesla parked across the street may have seen them.
The traffic camera saw their vehicle.
A doorbell camera caught them three blocks away.
Someone’s dashcam recorded the intersection.
A convenience store caught the same jacket twenty minutes earlier.
Police don’t necessarily need the target camera to identify somebody.
They can work outward.
That’s increasingly how modern investigations operate.
One dataset becomes a pivot into another.
Then another.
Then another.
Eventually the interesting question isn’t:
Did this camera identify somebody?
It’s:
How many independent systems observed the same person during the same period?
That’s a much harder problem to disappear from.
Don’t snitch on yourself
There’s also a considerably less technical form of OpSec:
Don’t manufacture evidence against yourself.
You generally don’t have to volunteer explanations to police merely because they ask questions.
People can politely assert their rights and ask whether they’re free to leave or being detained.
They can decline consent to searches.
Those are ordinary constitutional rights, not hacker tricks.
And if you’re participating in a lawful protest, knowing your rights is considerably more useful than pretending you’re Jason Bourne because you installed an encrypted messaging app.
The broader lesson is simple:
Assume anything you say, post, photograph, message, or record may eventually be seen by somebody you didn’t intend to see it.
That’s good security advice whether you’re attending a protest, conducting a penetration test, protecting a company, or simply existing on the modern internet.
The effective way to take the network down
Want to actually kill Flock?
Don’t attack the camera. Kill the contract.
A damaged camera gets replaced.
A terminated contract takes an entire jurisdiction off the network.
File public-records requests for:
-
contracts and invoices
-
camera locations
-
retention settings
-
sharing partners
-
user lists
-
audit logs
-
misuse investigations
-
breach notifications
-
policies involving protests
-
immigration requests
-
abortion investigations
-
journalists
-
federal access
Then make officials answer uncomfortable questions in public:
-
Does searching historical data require a warrant?
-
Who can search the system, and which outside agencies have access?
-
Can federal agencies query it directly or indirectly?
-
Is every search tied to a case number and reviewed?
-
Are audits routine or only performed after a scandal?
-
Can the vendor train models using locally collected data?
-
What happens when a credential or integration is compromised?
-
What would cause the jurisdiction to terminate the contract?
Then push for enforceable rules:
Warrants for historical searches.
Short retention periods.
No federal or out-of-state sharing without appropriate legal authorization.
No searches based on protected speech or lawful protest activity.
Real penalties for misuse.
Independent audits.
Elected-body approval before deploying new sensor types.
Sunset clauses forcing governments to periodically justify keeping the system.
And transparency reports that ordinary people can actually understand.
This works.
In August 2026, Florida revoked permits for Flock cameras installed on state roads and ordered them removed.
That doesn’t eliminate cameras on municipal roads or private property.
But it demonstrates something important:
Deployment is a policy choice.
It can therefore become a different policy choice.
Rep. Greg Steube subsequently introduced the FLAFO Act, legislation intended to require warrants for certain federal access to networked ALPR information and place privacy conditions on some federal grant funding.
Privacy is also one of the increasingly rare issues capable of creating unusual political coalitions.
Civil-liberties organizations.
Privacy advocates.
Libertarians.
Conservatives concerned about government surveillance.
Immigration advocates.
Journalists.
Gun owners concerned about location tracking.
People worried about reproductive privacy.
You don’t need everyone to agree about politics.
You need them to agree that the government shouldn’t quietly build a searchable record of where everyone goes.
The ACLU publishes a practical guide for challenging Flock and other mass-surveillance ALPR deployments locally.
Use it.
Build coalitions.
File records requests.
Show up at meetings.
Read the contracts.
Read the audit logs.
Ask uncomfortable questions.
And bring receipts.
Where to draw the line
We don’t have to choose between recovering stolen cars and preserving civil liberties.
Targeted tools operating with warrants, short retention, narrow access, meaningful auditing, and enforceable consequences for misuse can provide legitimate investigative capabilities without quietly turning ordinary travel into a privately hosted national intelligence feed.
Because the fundamental problem isn’t the camera.
It’s accumulation.
One photograph isn’t a surveillance state.
One license plate isn’t a surveillance state.
One trip through an intersection isn’t a surveillance state.
But hundreds of thousands of sensors producing searchable historical records of where millions of people traveled?
That’s something society should probably discuss before the database exists.
Systems also outlive the people who originally approved them.
Maybe you trust this administration.
Maybe you trust your governor.
Maybe you trust your sheriff.
Maybe you trust your police chief.
Fine.
They won’t be there forever.
Databases will.
Infrastructure will.
Integrations will.
And the next person sitting behind that keyboard inherits whatever power the last person built.
The cameras are watching the public.
The public should be watching the system.
Sources and further reading
-
ACLU: How to Fight Deployment of Flock and Other Mass-Surveillance ALPRs
-
AP: Illinois Investigates Plate Data Shared in Search for Woman Who Had an Abortion
-
WIRED: How an Atlanta Suburb Shared Flock Data With More Than 2,000 Organizations
-
Tom's Hardware: Flock Seeks Takedown of Researcher's Camera Map
-
ClickOrlando: Florida Revokes Permits for Flock Cameras on State Roads
