Flock Cameras, Warrants, and Who Bears the Cost
Flock cameras aren't really a safety-vs-privacy debate. They're a question about who absorbs the risk when surveillance has no warrant requirement.
Written by AI. Rachel "Rach" Kovacs

Photo: AI. Lev Zolotov
"Public safety or public surveillance?" is the wrong question. It frames this as a binary where you pick your team, and both teams think the other is either naive or criminal. The more useful question — the one that actually has traction — is this: who absorbs the risk when a surveillance system has no warrant requirement, makes errors it can't fully account for, and scales through data-sharing agreements most people have never heard of?
That's the question Dave Plummer, retired Microsoft engineer and host of Dave's Attic, spent a recent episode of Shop Talk wrestling with. He started by refusing to take a side, which predictably annoyed everyone. One viewer opened with: "You should take a side. What is wrong with you?" Plummer held his ground. His reasoning is worth sitting with, even if where he lands is not quite where I'd land.
What Flock cameras actually do
This matters because the debate often happens between people with very different mental models of the technology. Flock cameras are not uploading continuous video. Each time a vehicle passes, the system captures a still image, reads the plate, and logs an event: this plate, this location, this timestamp. That's the data unit. The privacy concern isn't any single image — it's that enough of those events, stitched together, construct a movement history. As Plummer puts it: "Out of a series of instantaneous images, they can construct a path for you in time, which basically amounts to surveillance of you."
That's the core distinction from a cop writing down plate numbers on a notepad. The notepad doesn't scale. A queryable database does. One viewer asked whether it would be any different if the state hired 50,000 officers to record plates manually — Plummer's answer was essentially: no, unless you give them a database. The problem was never the observation. It's the aggregation.
If you want a fuller picture of what Flock cameras capture beyond the plate itself, we've covered that ground separately.
The warrant gap is the actual argument
Here's where the comparison to cell phone tracking keeps tripping people up. Yes, your phone is dramatically more precise than a license plate reader. Yes, law enforcement can reconstruct your movements from cell tower data. But to do that, they need a warrant. Flock data — because it's captured in public, on public roads — currently requires no warrant to query, in most jurisdictions.
That asymmetry is what Plummer keeps returning to: "I would prefer that it requires exigent circumstances or a warrant, as opposed to just — I got a fish in the database today."
The warrant requirement isn't bureaucratic friction. It's the mechanism that forces a human to articulate probable cause before surveilling a specific person. Remove that, and you have a system that can be queried out of curiosity, out of personal animus, or out of institutional pressure — and the person being surveilled has no idea it's happening and no recourse if it's abused.
The MFA question Plummer raised compounds this. If Flock logins don't require multi-factor authentication, credential sharing becomes a real vector — not for exotic hacks, but for the mundane kind: a shared login passed around a department, an ex-employee whose access wasn't revoked. The technology being deployed at scale while the access controls lag behind is a pattern I've seen repeatedly in this space. It's not a hypothetical risk category.
The data-sharing problem nobody talks about
Individual Flock deployments are one thing. The sharing agreements are another. Municipalities can opt into data-sharing with neighboring jurisdictions. Plummer describes this as potentially "promiscuous" — Redmond shares with Bellevue, Bellevue shares with three other cities, and suddenly you have something approaching a regional or national movement database assembled from locally-approved cameras that residents voted for without understanding the aggregate effect.
This is where I'd push back on the "if you have nothing to hide" crowd more firmly than Plummer does. The argument assumes a stable legal environment where what's legal today stays legal tomorrow. It assumes the database is only queried by people acting in good faith. And it assumes that errors in the system are rare enough and consequential-enough to matter. All three assumptions are fragile.
On errors: The Institute for Justice has documented dozens of cases where innocent motorists were pulled over, detained at gunpoint, or jailed due to automated license plate reader mistakes. That's not a hypothetical harm from future misuse. It's current, documented harm from systems that are already deployed. Plummer's episode surfaced a vivid illustration from a viewer whose wife was billed for a toll road she never drove, because the system confused her Hyundai Accent's plate — GRIN — with a Harley-Davidson's plate reading GRIMM. Two N's versus two M's. Wrong vehicle type, wrong driver, wrong everything. That was a billing error. At a traffic stop, it's a different encounter entirely.
Ring cameras and warrants deserve a separate mention because viewers raised them in the episode. Amazon's practices around law enforcement requests have drawn sustained scrutiny from privacy advocates — The Verge reported in 2022 that Amazon had a form allowing police to request Ring footage without a warrant and without user consent. The full picture is more complicated than any single framing can capture, but the scrutiny exists for a reason, and it points to the same structural problem: these systems were built for consumer convenience, not for the kind of access governance we'd want from a public surveillance network.
"Strengthen the law" is correct but incomplete
Plummer's preferred solution is to harden legal protections rather than engineer restrictions into the technology itself. When a viewer proposed hashing license plate data so that bulk queries become harder, Plummer pushed back: don't limit what the technology can do, limit what people are legally permitted to do with it. His argument is that technical workarounds get circumvented — and he's right that any cryptographic approach will eventually face pressure from improving compute power.
But "strengthen the law" has a timeline problem. The cameras are deployed now. The data-sharing agreements exist now. The warrant gap is live now. Legal frameworks move slowly, survive court challenges unpredictably, and vary enormously by jurisdiction. In the interim, real people are being misidentified and real databases are being queried without oversight.
What Plummer doesn't quite reckon with — and what I think is the load-bearing question — is who absorbs the cost of that lag. The answer, consistently, is not the municipalities that deployed the cameras and not the companies that sold them. It's the people in the database who had no say in the matter and won't know they were surveilled unless something goes wrong.
What you can actually do right now
This is the part most coverage skips, and it's the part that matters. The Flock debate doesn't have to be a spectator sport.
If you want to know whether your municipality uses Flock cameras, or has data-sharing agreements with neighboring jurisdictions, you can file a public records request — a FOIA request in the US, an FOI request in Canada. Plummer and his co-host Glen Hodges discussed this in the episode, and it's a legitimate and underused tool. You're asking a public agency about a publicly-funded system. That's exactly what records laws are for.
If your city council is considering a Flock deployment, that's a procurement decision — and procurement decisions have public comment periods. Asking specifically about warrant requirements for queries, about data retention limits, and about data-sharing scope is not obstructionism. It's the kind of oversight that makes the difference between a system with guardrails and one without.
If your city already has cameras deployed and you want to understand the terms, that contract is almost certainly a public record. Request it.
The cameras aren't going away. The question is whether the rules governing them get written by the people they surveil, or by the people who profit from deploying them.
Rachel "Rach" Kovacs is Buzzrag's cybersecurity and privacy correspondent.
We Watch Tech YouTube So You Don't Have To
Get the week's best tech insights, summarized and delivered to your inbox. No fluff, no spam.
More Like This
New Siri Indexes Your Private Data. Now What?
Apple rebuilt Siri's on-device index from scratch. It's genuinely better. It also reads your messages, mail, and photos. Here's what that actually means for you.
Vercel's Portless Tool: Weekend Project or Real Solution?
Vercel Labs released Portless to eliminate localhost port conflicts. Does this weekend project solve a real problem, or create new ones?
The Engineer Who Got Kicked Out of College—Then Hired
James Everingham's tech career started with a 0.0 GPA and an FBI visit. His path from teenage hacker to Instagram's head of engineering defies convention.
Apple TV 4K 2026: Gaming Console or Privacy Liability?
Apple's upcoming TV box promises AI intelligence and console gaming. But three years without updates raises questions about what's really driving the delay.
Air Force Engineer Charged Over Flock Camera Destruction
Jeffrey Sovern faces felony charges for destroying Flock Safety cameras in Virginia. His crowdfunded defense has become a flashpoint in the surveillance debate.
Flock Cameras Track Far More Than License Plates
Flock Safety's AI-powered cameras are spreading fast across U.S. cities—and they're capturing far more than license plates. Here's what's at stake.
Why Most Business Dashboards Fail (And How to Fix Yours)
Most analyst dashboards fail not from bad data or questions, but from poor preparation and visualization choices. Here's what actually matters.
35 Self-Hosted Apps That Actually Replace Your SaaS Stack
From recipe managers to AI memory systems, these GitHub projects let you own your data without sacrificing features. A security-focused look at what works.
RAG·vector embedding
2026-08-01This article is indexed as a 1536-dimensional vector for semantic retrieval. Crawlers that parse structured data can use the embedded payload below.