The video above walks through a striking claim: researchers say they were able to open up a Flock Safety license plate reader, pull an encryption key off it, and access tens of thousands of video clips and more than a million images. If accurate, that is not a small bug. It is a reminder that the cameras watching your daily commute are, at the end of the day, computers bolted to a pole, and computers can be broken into.
Why this matters beyond one camera
Automated license plate readers are marketed as a tool for police to solve crimes and find stolen cars. But every camera is also a data collection point, storing images of your plate, your car, sometimes your location and travel patterns over time. That data has real value, not just to police departments, but to anyone who wants to track where a specific vehicle has been. When a company builds a nationwide network of these cameras, the security of each individual unit becomes a piece of a much bigger puzzle. A weakness in one device is not just a local problem, it is a question about the whole system’s design.
Encryption keys are supposed to be the last line of defense
In theory, encryption is what keeps stored footage safe even if someone gets physical access to a device. If a key can be pulled out of hardware in the field, that protection is only as strong as the hardware itself. This is a well-known challenge in physical security research generally: devices deployed outdoors, on public poles, with limited armed guarding, are inherently harder to protect than servers locked in a data center. That does not mean ALPR vendors get a pass. It means the public deserves clear, verifiable answers about how these systems are secured, tested, and audited.
What everyday people can actually do
Most residents never get a vote on whether a Flock camera goes up on their street. City councils and police departments usually make that call, often with little public debate. That is exactly where accountability has to start. Ask your local council whether they know how footage is encrypted, who audits it, and what happens if a device is compromised. Check whether cameras near you are documented on the map, learn the basics of how these systems work on our learn page, and if you want to push for real oversight in your community, our take action page has concrete steps.
The bigger picture
One reported hack does not prove the entire nationwide network is unsafe, but it does prove the risk is not theoretical. Surveillance infrastructure built at this scale needs security that matches its ambition. Until that is demonstrated publicly and independently, skepticism from residents is not paranoia, it is due diligence.
Independent, ad-free — and reader-funded
No ads, no paywalls, no selling your data. What this costs is server bills and the data services behind the map, the Docket, and the archives — and every dollar readers chip in goes to exactly that: keeping DeFlock The USA up, current, and ad-free.
Support us on PayPal or scan the code, or Venmo @deflocktheusa