This is pure laziness aka “reduced time to market” on the part of Flock.

It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.

Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.

Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.

Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.

The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false.

If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.

Don’t worry, your elected representatives won’t be bothered by trivialities such as facts either way.

They can be recalled and/or replaced, as many have who voted for data centers.

They fought against datacenters. Now they are running for local offices - https://www.theguardian.com/us-news/2026/sep/15/datacenters-... - September 15th, 2026

https://news.ycombinator.com/item?id=49375000 (citations)

Only a handful of states have any concept of a recall election.

Indeed, have to wait for elections when recalls aren’t an option. Elections arrive eventually.

Exactly. It helps they also control who can even run for office in any meaningful way. Nobody fights the left harder than Democrats. Good luck finding a representative that is against data centers, flock, Israel, congressional stock bans and pausing and regulating AI, views overwhelming popular with the majority of the actual American public.

My experience is that nobody fights the democrats harder than "leftists".

Funny. In my experience, nobody fights the “leftists” harder than the Democrats. I think the Republicans fight the Democrats harder than anyone else, and aside from the “leftists”, no political group seems to really fight the Republicans.

You are misunderstanding basic political terminology then, if you think it's somehow odd that leftists are against Democrats. Democrats and Republicans are both capitalists and liberal in the classical sense, both of which leftists oppose.

>Good luck finding a representative that is against data centers, flock, Israel, congressional stock bans and pausing and regulating AI, views overwhelming popular with the majority of the actual American public.

That is rapidly becoming Democratic party orthodoxy. At the very least there are a sizable number of Democrats who fit that.

Don't know why you're getting downvoted, but hackernews is very anti-democratic in nature. One thing politicians quickly realize, especially local ones, is that you do have to be accountable to voters at the end of the day. One or two bad stories is enough to sink a local race too, or at minimum require a massive spend to overcome the negativity.

Local politics is where you understand how effective a handful of people can truly be.

Happy to read people are understanding the true power they have collectively instead of as individuals.

Oh yeah, totally agree, the HN zeitgeist is what it is.

It’s not laziness, it’s hyper focus on compliance. CJIS is the policy maintained by the FBI that handles information security, which is derived from standards built around paper.

Adding more weirdness, the details get worked out by each state.

My guess is they encrypted whatever is criminal justice information (license plate hotlists, etc) or protected by local laws (DMV data) and left the rest to make it easier to deploy and service. Remember pictures of you or your car taken in public are not protected or in scope.

Police tech is garbage and usually driven by federal grant spending. So it’s going to be interesting to see how Flock and Axon grow the business as it turns into a service model.

My problem is that Claude kept screaming across several sessions that it echo'ed a default password for a local, ephemeral development container into a session across SEVERAL sessions.

I get dinged continually for a vendor supplied container that writes an appropriately scoped access key to disk in plain text on startup (we are working to eliminate it but it requires migrating to an entirely new way of doing things the vendor only released earlier this year and I got derailed by other priorities).

So like if established enterprises using off the shelf scanning software are breathing down my back about this...what the actual hell is happening inside flock that this was fine. Lol.

The question is, why should they care at all? Will this hurt their business?

Any breach of security on a system like this is a big flashing red-alert to me.

If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.

Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.

Getting persistent access to Flock's internal network is a high-priority item for every US adversary, who doesn't want free intel collection on the movements of persons of interest? Knowing who the FBI and local cops are monitoring in is the counter-counter-intelligence cherry on top of a self-inflicted dragnet surveillance cake.

Any entity with access to flock servers can virtually stake-out anyone/everyone driving past Flock camera to monitor their movements. In a hot war, this would provide actionable data to support assassination via road-side bomb/drone strikes.

I mean... currently any cop can do that, and it's a lot easier to bribe a single cop than to break into flock network.

https://edition.cnn.com/2026/08/26/us/flock-kentucky-police-...

A single cop can do it 2000 times it seems before they get caught

And it's not a lone case: https://www.washingtonpost.com/technology/2026/08/02/how-pol...

.. with friends like these, who needs enemies

That's why you or I would care, but that doesn't answer the question of why they would.

Large companies tend to be amoral. Unless it affects them monetarily (possibly indirectly) they're not going to care. Given what they do to make money, I don't see any of these things hurting them.

It's a red-alert to you and me, but Flock won't care. People already don't want these cameras in their cities, but police departments buy them anyway. What does it matter if there's one more reason you don't want them?

Apparently police are accessing the network via their personal devices. I highly doubt their security practices online are any better than this. I wouldn't be surprised either to see things that chinese manufacturers do such as intentional back doors.

Overall this goes from disappointing to fairly repugnant.

Allegedly you can buy credentials on the darkweb to perform national searches. Might explain why some of the logged reasons for recent searches were “LMAO”

The normal explanation is plenty, unless you’ve never met, read about, or heard anyone talk about, law enforcement officers (who are human beings - for better and for worse).

How many of us have had coworkers who put something like that into a commit message? And that's a message that's at least notionally supposed to be helpful to you or your coworkers, rather than existing purely for the purposes of oversight you don't want in the first place.

I would expect law enforcement coworkers to understand the law, department procedure, and public requests for their data. That’s expecting too much from the academy, I guess.

Those that fail to meet standards should be fired to spare the taxpayers from the lawsuits coming from AI-assisted complainants.

It’s also too much for Flock’s YC-funded technology to implement a field filter that rejects “LMAO” as a valid request.

At the very least, your local staff’s nationwide stalking credentials being harvested by phishing and abused by others should carry criminal negligence penalties. Governments should pass that liability onto this YC-funded startup company.

It’s a federally protected right to skip over law enforcement officers candidates because they rank too high on an aptitude or IQ test.

Reasonable people would expect what you expect. We are not reasonable people.

This meme will not die, and here you can see it blossoming into something even weirder.

There is one (1) case in the literature, back in the early 2000s, where a department rejected a candidate as overqualified based on a cognitive assessment; the rejected applicant took that department to court and lost.

That's it; that's all the evidence.

Against that: most police departments around the country administer written tests with general cognitive components for which there is a floor score and no ceiling (the POST, the NTN, &c). And virtually no departments --- none I'm aware of --- administer IQ tests.

From all this, we've now got "a federally protected right"?

Yes, that’s how court / legal precedent works - for better and for worse.

Feel free to consult an attorney.

Edit: I thought the case went further up - but, “persuasive precedent” for other jurisdictions now exists all the same.

Edit2: since I’m seeing the username of someone with a decent clue,

> and no ceiling

was there one on paper for the hiring standards of the dept in the case in question?

Does that matter?, if there’s no legal issue with using it as a disqualifying factor? - for any candidate - whether or not they even score well?

Literally the only thing you know here is that one department didn't like one candidate and came up with a reason to deny him based on cognitive overperformance. For all you know, they didn't like his hair color, and came up with an excuse. And that's it: out of over 15,000 police departments in the US, almost 1,000,000 sworn officers, and over 25 years, this is the evidence you have for the claim that there's an enshrined "right" to reject police officer candidates who are "too intelligent".

It's an Internet urban myth. I'm just stepping in to call it out as such.

That it’s legal precedent is not Internet urban myth lol - regardless of the side-story of how the precedent came to be.

Many moons ago, I was involved in the technical side of volunteer work for domestic violence victims escaping abusive relationships with e.g. law enforcement (cops), who even fifteen years ago had sweeping powers to track and stalk their victims. Things like actual anonymous burner phones and the ability to e.g. create new email accounts without government identification were critical to the process of getting these people out safely, or alive, without fear of retaliation.

I can't even imagine how difficult this job must be nowadays, with bullshit like Flock spanning hundreds of police departments participating in their nationally-linked database. I have zero sources for what I'm about to say, but my instinct is that the political machines (expanding powers hidden behind "think of the children") behind how technology is evolving today has gotten people killed.

Quite potentially, yes. Their name is already mud among many voters, if they're shown to be treating data insecurely then that's another reason why local governments might consider terminating contracts with them.

Feels like their purpose is to test the boundaries, take the hits, and eventually sell off

They want the good, bad and ugly to flock to them as it were and vaporize them so Axon and Motorola Solutions can just pick up right where they left off. And people will just ignore or forget it because it's not the same company.

Is there any recent example of a company getting breached and its data exfiltrated, where the business was actually hurt? I predict we'll get a standard boilerplate "We take security very seriously" press release, a narrative that blames the evil hackers entirely and not the company's negligence, and then that will be that.

Would the DNC in the last US national election count?

was there really any meaningful fallout though?

I really hate how Product Managers somehow get to take the reins of engineering teams instead of having to sell them product ideas.

It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.

Because software engineering is not professional engineering.

Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult.

Do you feel like an inadiquate imposter or something? I'm assuming you work in software.

Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design.

Or read about engineering failures like flight QF32 (mostly a success story):

  A paperwork review showed that the required signatures were missing from 131 out of 138 retrospective concessions issued between 2009 and 2011
https://admiralcloudberg.medium.com/a-matter-of-millimeters-...

Australian Quantas, with a UK Rolls Royce engine on an Airbus, with engines maintained in Aussie.

Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems.

Certification matters less than you might think across international borders.

Perhaps I'm a cynic, but beliefs in certification seem so irrational to me. What is it? Jealous desires for status? Desire to have guilds/gatekeepers? Complete misunderstanding of how safety occurs in "real" engineering?

Your conclusion seems at odds with your evidence: the quote you reference indicates that a professional engineer was meant to examine the 'retrospective concessions' and did not. The result was that no qualified engineer was taking responsibility for their quality. Fixing the process meant getting credentialed engineers to assess and incur liability for the solutions, which is how the professional engineering licensure system is supposed to work.

>Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems.

I mean, you make my point. At no point did I say engineers are the only required component, but without the responsibility of an engineer signing off on its technical adequacy we have loads of historical proof that people end up dead far more often.

You believe signatures by engineers matter.

That is your belief, but I've never seen that belief backed by fact.

Most open source software disowns liability in CAPS in the license. Yet somehow FOSS like Linux gets used for safety critical infrastructure.

Microsoft would love certification requirements for engineers - that would kill open source to their conpetitive benefit.

Do you honestly think if we required Microsoft Certified Professionals to sign the internals of Microsoft OS then Windows would be more secure or reliable?

The bigger issue is that signatures and criminal consequences hardly matter across jurisdictions.

The capitalist issue is that businesses want scapegoats when things go wrong. That would be the outcome of signatures: engineers as fallboys for systemic failures across organisations.

Note how often pilots are blamed for accidents due to the design of planes.

It is just an idealistic belief based on feelies that software certification would achieve the goals you imagine it would.

Signatures are an anachronism: from an alien past.

International business uses different mechanisms for safety.

Our world is intertwined complexity. You somehow think that the buck should stop at engineers?

If engineers signed off on everything then we'd have no more disasters like New Orleans floods?

Who signed what for the Grenfell towers tragedy? Which engineers were reprimanded? Did they decide that more signatures would help prevent future disasters?

That’s because computers are Turing complete anything is technically possible and comes down to the time quality cost triangle. Most management thinks they can optimize that triangle by squeezing the living bejesus out of their teams.