Flock Cameras: Public Safety Tool or Mass Surveillance Network?
You’ve probably driven past one and never noticed.
A small camera on a pole. At the entrance to a neighborhood, near an intersection, outside a business. It doesn’t look like a traffic camera, so nobody looks twice. A lot of them are made by a company called Flock Safety, and right now they’re at the center of a fight that should matter to you a lot more than it probably does.
So let’s start with the basics, because most people have driven past a hundred of these things without knowing what they actually do.
Flock makes what’s called an automated license plate reader — ALPR for short. It’s not complicated. A car drives by. The camera captures the plate, the time, the location, sometimes the make, the color, other details about the vehicle. That information gets stored, and it becomes searchable, indefinitely, by anyone with access to the system.
Say police are hunting a stolen truck. Instead of hoping an officer happens to spot it in traffic, they search the system and find out it passed a specific camera fifteen minutes ago. Now picture an Amber Alert, or a partial plate from an armed robbery, or an elderly man with dementia who drove off and hasn’t been seen in six hours. I understand exactly why law enforcement wants this technology, and I’d want that camera running too if it was my kid. There’s real public-safety value here. I’m not going to pretend otherwise just to make a cleaner argument.
But here’s the thing about a single camera at a single intersection catching your truck at 8:17 on a Tuesday morning — that’s not mass surveillance. I wouldn’t lose sleep over one observation.
Now multiply it. Cameras across your city. Then the next city. Then your entire state. Then the whole country. Individually harmless observations start stacking into something else entirely. Leave the house at 7:48. Pass a camera near the office at 8:12. Show up near a medical clinic at noon. Back at the office by 1:22. Leave the area at 5:34. Near a restaurant at 6:03. Home by 7:51. Do that Wednesday. Do it Thursday. Do it Friday.
At some point you’re not recording license plates anymore.
You’re reconstructing someone’s life.
Flock isn’t small. Reporting puts the network north of 120,000 cameras nationwide now, with thousands of agencies plugged in and sharing access. This is where it stops being theoretical.
Here’s the part most people miss, and it’s the whole ballgame. The database doesn’t start with a suspect. We’ve all been conditioned to think about surveillance one way — a crime happens, a suspect emerges, police investigate that specific person, and under real legal constraints, they get authorization to watch them. Targeted. That’s the model we grew up believing in.
ALPR flips it. Collect everyone first. Store it. Search it later, if and when someone becomes interesting. The camera doesn’t know who’s committing a crime. It photographs the guy driving to work, the stolen truck, the soccer mom running carpool, the pastor, the drug dealer, the armed robber — indiscriminately. It photographs you. Collection happens first. Suspicion happens later. That ordering is the entire problem, and “but it helps solve crimes” doesn’t make it disappear.
I know the counter-argument, because I hear it constantly: a license plate is already public, anyone can see it. That’s true. When I drive down a public street, I have zero expectation that nobody sees my truck. But scale changes the math completely. There’s a massive difference between a cop glancing at my plate once, in passing, and a machine quietly building a permanent, searchable record of everywhere that plate has ever been observed.
Think about it this way. Someone sees you walking down the street with a coffee — no big deal, nobody cares. Now imagine someone follows you every single day for a month, writes down everywhere you go, and files it in a database that anyone with the right access can search whenever they want. Those aren’t the same thing. Not even close. The individual observations all happened in public. It’s the aggregation that turns them into something dangerous. Patterns tell stories that no single sighting ever could — where you sleep, where you work, which doctor you see, which church you attend, which meeting you went to, which treatment center you visited, whose driveway you’re parked in at 11 p.m., whether you were at that protest, whether you saw a divorce attorney, who you’re always with. One plate doesn’t say any of that. A big enough pile of them does.
This would still be a hypothetical concern, worth debating in the abstract, except it already happened. Repeatedly.
A major Washington Post investigation published this month found at least 50 officers nationwide charged with or accused of misusing plate-reader networks — in roughly half those cases, to track wives, girlfriends, exes, and people they had personal interest in, nothing to do with actual police work. One woman discovered her officer ex-boyfriend had searched her location 600 times. In Texas, a Lufkin officer was indicted on 100 felony counts after allegedly using the system to track eleven different people, for nongovernmental reasons, on dozens of occasions over nearly two years. In Massachusetts, an officer is accused of running unauthorized searches on an ex-partner; the town cut ties with Flock and pulled its last camera.
Most officers aren’t doing this. I genuinely believe that. It doesn’t matter. If you build a system powerful enough, someone will eventually abuse it. That’s not cynicism — that’s Information Security 101. We don’t design access controls around the assumption that everyone with a badge or a login will always behave. We design them because humans are humans, and some percentage of people will always take the shortcut when nobody’s watching.
Then there’s the sharing problem, which most people never think about at all. Your local department’s camera doesn’t necessarily stay local. Flock’s real value, from a law enforcement standpoint, comes from networking agencies together — other jurisdictions can search, regions can cooperate, a kidnapper doesn’t stop driving because he crossed a county line. Fair enough. But surveillance doesn’t respect jurisdictional lines any better than criminals do, once the networks connect. Flock itself admitted that some California networks were inadvertently accessible to out-of-state agencies during 2025. They said they regretted it. They added safeguards. That matters because states don’t all play by the same rules — abortion, immigration, marijuana, firearms, protest activity. Legal in one place, aggressively prosecuted in another. So now you’ve got a real governance question that isn’t technical at all: who gets to search data collected about the people in your town? Local PD? The sheriff? State police? The feds? Another state entirely? A private company? And who decides that — the chief, the council, Flock, a judge, you?
Los Angeles is the current flashpoint on this. Concern grew that plate data could feed federal immigration enforcement, and LA’s mayor called for LAPD to stop using Flock devices over exactly that worry. I’m not making a point about immigration policy here — that’s not the argument. The argument is that governments change. Policies change. Prosecutors change. Presidents change. Police chiefs change. What’s an acceptable use of a surveillance system today might look completely different in ten years. Infrastructure outlives intentions. We’ve learned that lesson before, and we keep needing to relearn it.
And nobody’s getting a warrant for any of this. If police want to search your house, the Fourth Amendment means something — real protections, real process. Plate-reader searches usually don’t work that way. Officers generally don’t need a warrant to pull this kind of location history, and the laws governing it vary wildly depending on where you live. So here’s a constitutional question nobody’s answered cleanly: at what point does pulling someone’s historical location data become the same thing as tracking them? One observation is fine. Ten? A hundred? A month of movements? A year? The Constitution’s authors never imagined this problem. The principles still apply. We just haven’t figured out how yet.
To be fair — and I try to be fair even when I’m frustrated — Flock hasn’t ignored the criticism. In August, they announced tighter auditing, a requirement that searches be tied to actual case numbers, better detection of abnormal search activity, and a cut in standard data retention from 30 days down to seven. Those are real improvements. They’re also a quiet admission that the original controls weren’t good enough. Critics still argue it doesn’t touch the core issue, and I think they’re right, because better auditing doesn’t answer whether the collection should be happening in the first place.
This is where the two sides usually talk past each other. Privacy advocates say it’s mass surveillance. Law enforcement says it catches criminals. They’re both correct. A technology can be genuinely effective and genuinely dangerous at the same time — and honestly, the more effective it is, the more scrutiny it deserves, not less. A system that doesn’t work isn’t much of a threat to anybody. A system that can accurately reconstruct where millions of vehicles have traveled is a different animal entirely. So the question isn’t whether Flock works. It clearly does. And it’s not whether police should get to use technology. Of course they should. The question is what rules should govern something this powerful.
One thing I actually find encouraging: this doesn’t split down the usual political lines. Civil libertarians on the left worry about immigration enforcement, protest surveillance, reproductive rights. Civil libertarians on the right worry about government tracking, firearms enforcement, federal overreach. Different reasons, same underlying question — how much power should government have to watch ordinary people? That’s a conversation worth having without anyone retreating into their tribe.
And communities are starting to push back for real, not just complaining online. Some are ending contracts. Others are tightening usage rules or demanding public hearings. By recent counts, somewhere around a hundred local governments across the country have cut ties with Flock or similar systems over privacy and governance concerns. In Hood County, Texas, commissioners voted in April to end their contract, and in August, a constable’s office finished the job — unplugging and covering the cameras themselves rather than waiting on the paperwork. People are noticing the cameras now. They’re asking questions. That’s healthy. That’s how this is supposed to work.
Let me be straight about where I actually land on this, because I don’t want to leave you thinking I’m anti-Flock. I’m not saying ban the cameras. I’m not saying police shouldn’t use modern technology. If someone takes my kid and a Flock camera helps find him, I’m going to be grateful that camera existed. If my truck gets stolen and it’s recovered in thirty minutes because a camera flagged it, good. Technology can absolutely make us safer.
But “this technology has value” and “government should deploy it without meaningful limits” are two completely different arguments, and letting anyone collapse them into one is exactly how we end up with infrastructure we can’t undo. We can support law enforcement and demand real controls. We can care about crime victims and care about privacy. Both. Not one traded away for the other.
So what does responsible use actually look like? I don’t have every answer, but any community deploying this technology should be able to answer some basic questions before the contract gets signed, not after the first scandal. Who can search the system, and why does that access exist? Is curiosity about an ex impossible, or at minimum easy to catch and punish? Is every search logged, and are those logs actually audited, not just collected and forgotten? Does every search require a documented reason? How long is the data kept — seven days is a different world than seven years. Who can the data be shared with — another state, the feds, immigration authorities, private companies? What happens the first time someone abuses it? Did the public know these cameras were coming before they went up? Did elected officials actually understand what they were approving? And the one that matters most: can the public still change the rules later, or is this permanent the moment the contract’s signed?
I look at this whole thing through a security lens, because that’s the lens I’ve spent thirty years building. Security people love to obsess over whether something is technically secure — encrypted, MFA required, patched. Good questions. Incomplete ones. A perfectly secured system can still be used irresponsibly. Sometimes the biggest threat isn’t an unauthorized person breaking in. It’s an authorized person using their legitimate access for something it was never meant for. Flock can have flawless encryption and still have an officer, using his own valid credentials, stalking an ex-girlfriend. That’s not a cryptography failure. That’s a governance failure. An accountability failure. A human failure. Technology is rarely the actual problem. Irresponsible use of it always has been.
We’ve watched this movie before. After 9/11, the U.S. rapidly expanded surveillance in the name of stopping terrorism. Understandable, at the time — people were scared, the threat was real. But once infrastructure exists, something predictable happens: the reasons for using it expand. Mission creep. A tool built for terrorists gets used on serious crimes, then ordinary crimes, then administrative cases nobody imagined when it was first approved. Not every time. Often enough that we should’ve learned the lesson by now. Here’s the uncomfortable part — technology remembers what governments forget. The politician who approved it retires. The police chief moves on. The vendor gets acquired. The law changes. The climate shifts. The infrastructure stays exactly where it is. “Trust us” was never a real security control. It never will be.
So strip away the marketing, the political noise, and the activist slogans, and here’s the actual question — the one that doesn’t come with an easy emotional answer built in. Should government routinely collect location data on millions of innocent people, just in case one of them becomes interesting to police someday? Not “do you support cops.” Not “what are you hiding.” Not “wouldn’t you want the camera if it was your kid.” Those are shortcuts designed to end the conversation before it starts. The real question is harder — who gets to search it, how long it sits in a database, who it can be shared with, what happens the day it’s abused, and whether the public can still change the rules after the ink’s already dry.
I’m not against these cameras. I’ve said that twice now because I mean it. But I’d rather have that conversation before the infrastructure exists than after we’ve already given something away we can’t get back.
A hundred or so communities have already walked away this year. That’s not paranoia. That’s people finally asking the question before it’s too late to matter.
Has anyone asked it where you live?