EP 275 Oops they did it again on the IT Privacy and Security Weekly Update for the week ending Janu
The short version: Archimedes Insights reports Flock's Condor ALPRs were caught livestreaming feeds and admin controls with zero passwords, and the researchers who found it say they got surveilled and fired for their trouble.
Our Take
Give credit to Archimedes Insights for flagging this one on their weekly roundup: at least 60 Flock Safety Condor cameras were sitting wide open on the internet, no password, no encryption, just live feeds and admin panels for anyone who stumbled onto the right IP address. This is the same company that keeps telling cities, courts, and reporters that its network is locked down tight and only accessible to vetted law enforcement. A vendor that can't secure the boxes bolted to your telephone poles has no business holding years of your travel history.
What really should stop you cold is the second half of the story: the researchers who disclosed this responsibly say they were surveilled and lost their jobs for it. That's the actual threat model of mass ALPR networks in a nutshell. The system isn't just vulnerable to outside hackers, it's also wired to punish the people who try to hold it accountable. When a private surveillance company's incident response looks more like retaliation than remediation, that's not a bug, that's the business model.
Unsecured cameras streaming plate data to whoever finds them isn't a hypothetical, it's happened, and it will happen again as more of these units go up with minimal oversight. If you want to know how many of these cameras are already watching your town, check our camera map, and if you're ready to push back on a local Flock contract, our take-action resources can help you get started.
This is DeFlock The USA’s original commentary. The video above is the work of Archimedes Insights, published on YouTube — full credit to the creator.