The defining feature of automated license-plate surveillance is not that it watches suspects — it watches everyone, indiscriminately, and keeps the record long after the point of any actual investigation, which is precisely the mechanism that turns an ordinary policing tool into something closer to a national tracking grid.
Key Points
- Flock Safety’s cameras now number in the tens of thousands across thousands of U.S. communities, scanning license plates and vehicle characteristics around the clock and feeding the results into a searchable, nationwide database.
- Federal vulnerability records list at least fifteen documented security flaws in Flock hardware, two rated critical at 9.8 out of 10, including hard-coded credentials and an exposed debug interface.
- State audits and class-action lawsuits allege the network has funneled driver data to federal immigration authorities and out-of-state agencies in violation of state privacy statutes.
- Flock has responded with retention cuts and mandatory multi-factor authentication, but critics argue these are policy patches on an architecture built for mass collection, not consent.
- The underlying legal question — whether warrantless, networked plate-tracking amounts to the kind of pervasive search the Supreme Court restricted in Carpenter v. United States — remains unresolved and increasingly urgent.
How the Network Actually Works
Automated license plate readers are not new; police have used stationary and mobile scanners for two decades. What distinguishes Flock, the Atlanta-based company founded in 2017, is scale and connectivity. Its solar-powered, cellular-linked cameras capture not just plate numbers but a “vehicle fingerprint” — make, color, decals, dents, even unplated cars — and upload it to cloud servers where a single query can ping tens of thousands of devices across state lines simultaneously. That architecture is the product’s selling point to law enforcement and its central liability to privacy advocates: the same infrastructure that lets a detective find a stolen truck in another state also lets any authorized user reconstruct a stranger’s daily movements without ever obtaining a warrant.
Retention policy matters enormously here, because it determines how long that reconstructed history persists. Flock’s standard default was 30 days until backlash pushed the company to introduce a 7-day option and an “Evidence Mode” restriction, changes its CEO framed publicly as proof the company is “not Big Brother.” Whether a week is meaningfully different from a month, when the system still logs the location of nearly every passing vehicle, is the crux of the ongoing dispute — and it is a dispute the company has not settled so much as narrowed.
A Documented Security Problem, Not a Speculative One
Separate from the privacy debate is a harder, more technical set of facts: Flock’s hardware has been repeatedly shown to be poorly secured. The National Vulnerability Database, maintained by the Department of Homeland Security’s cybersecurity arm, lists CVE-2025-47822, an on-chip debug interface with improper access control in Flock’s license-plate readers, and CVE-2025-47818, a hard-coded password baked into the company’s gunshot-detection devices. Independent trackers tally at least fifteen separate CVEs across Flock’s product line, two of them rated 9.8 out of 10 in severity. Security researchers, including the widely viewed investigation by musician-turned-security-researcher Benn Jordan, demonstrated that specific button sequences could grant shell access to camera hardware in under thirty seconds, and that some units ran on an Android operating system discontinued by Google in 2021. Flock’s public response has largely been to dispute the framing of these findings rather than the underlying vulnerability data itself, telling one Texas city council that the company has never been “hacked” — a distinction that sidesteps rather than refutes the documented flaws.
Where the Legal and Political Fights Are Concentrated
The most consequential allegations concern who gets access to the data once it’s collected. An Illinois state audit found that Flock allowed U.S. Customs and Border Protection to reach into state camera networks in violation of state privacy law, prompting the company to pledge changes. The Los Angeles Police Department suspended its own use of the system after an inspector-general audit flagged uncertainty over data control and potential sharing with immigration authorities. Class actions in California allege the company enabled out-of-state and federal agencies to search state databases in violation of the state’s ALPR Privacy Act, and a Boulder, Colorado lawsuit argues that even a modest 31-camera deployment lets police catalog residents’ movements without warrants. A separate federal complaint documented individual officers running well over a thousand searches apiece, illustrating what the filing calls the gap “between retrospective auditability and timely intervention” — meaning the system can show, after the fact, that someone misused it, but does little to stop the misuse as it happens.
That gap has already produced concrete harm rather than hypothetical risk. Reporting has documented officers using the network to track ex-partners, a misidentified plate that led to a wrongful police stop, and a woman flagged repeatedly for suspected package theft without due process. These are not edge cases dreamed up by critics; they are the predictable consequence of a system engineered for maximum reach and minimum friction, sold into more than 5,000 agencies before most of the legal and technical guardrails were built.
I want stolen cars and missing people found. That is not the argument.
The hypothetical fear was made manifeest in Sheboygan. The city council bought Flock for crime. Then Flock tried to sell the city five years of speed and traffic data from those same cameras. The mayor says… pic.twitter.com/HXtOCTbC7E
— Nemo Stone (@NemoGneiss) September 6, 2026
The Company’s Case, and Why It Only Partly Answers the Concern
Flock’s defense is not without substance. The company points to its own 2025 Impact Census, which claims the network supported more than a million investigations and helped locate over 10,000 missing people, and it emphasizes that access is restricted to authorized, case-based searches controlled by local agencies rather than the company itself. Since the backlash intensified, Flock has cut default retention, added mandatory multi-factor authentication, and expanded audit logging. Those are genuine, verifiable policy changes, not empty gestures. But they address the symptoms of misuse — who can log in, how long data sits — rather than the structural fact that the network exists to scan the overwhelming majority of vehicles that have committed no crime, a pattern legal scholars have flagged for years as the core constitutional tension in ALPR technology. That tension traces back to a body of Fourth Amendment case law the technology has outrun. The Supreme Court’s 2018 Carpenter decision required a warrant for extended cell-site location tracking precisely because aggregated location data reveals a “pattern of life” no single observation could. Flock’s national query system does something structurally similar across tens of thousands of cameras at once, which is why courts, state legislatures, and now several attorneys general are actively litigating whether the technology needs the same constitutional guardrail — a question that will likely take years, and several more lawsuits, to settle.
Sources:
nypost.com, salvacybersec.medium.com, nexanet.ai, eff.org, upguard.com, nvd.nist.gov, deflock-deerpark.org, classaction.org, wrdw.com, app.opencve.io, simeononsecurity.com



