Hi everyone,
This week on Shared Security, we’re talking about Flock cameras, automated license plate readers, and the uncomfortable gap between how surveillance technology is sold and how it can actually be used once it is installed.
The hook is a 404 Media report about police allegedly using a Flock camera image to issue a traffic ticket to a motorcyclist. On the surface, that may sound small compared with serious-crime investigations. But that is exactly why the story matters. Flock and similar ALPR systems are typically pitched as tools for finding stolen cars, wanted suspects, missing people, or serious threats. When that infrastructure is used for routine traffic enforcement, it becomes a clear example of mission creep.
In the episode, we talk through the bigger privacy problem: a license plate reader is not just “a camera in public.” It can become part of a searchable database showing where a vehicle was seen, when it was seen, and which agencies or vendors can access that data. That changes the privacy calculus. A single public observation is one thing; a retained and searchable movement history is something else entirely.
Kevin makes the trust point bluntly: if the public conversation starts with a narrow claim about what the system is for, but the real-world uses keep expanding, communities have every reason to be skeptical. Tom brings in the local-governance angle: residents should be asking about retention periods, audit logs, sharing agreements, warrants, allowed uses, vendor access, and whether traffic enforcement, immigration enforcement, or out-of-state sharing is explicitly prohibited.
We also look beyond Flock itself. Some cities have reportedly responded to Flock controversy by replacing Flock with another ALPR vendor. But changing vendors does not automatically solve the surveillance problem. The real questions are policy, oversight, transparency, enforcement, and whether residents knowingly approved the system that is actually being used.
The episode also touches on where this can go next: rideshare dashcam surveillance proposals, mobile ALPR collection, and new technology that could associate nearby phones, smartwatches, AirPods, or other device signals with identifiable vehicles. If license plate readers start becoming multi-sensor location-intelligence systems, communities need to ask much more specific questions than “do we have cameras?”
The practical takeaway: check whether your city, HOA, school district, shopping center, or police department uses Flock or other ALPR systems. Then ask what data is collected, who can search it, how long it is retained, whether it is shared, whether searches require a warrant or case number, and whether public audit logs prove the rules are actually being followed.
Links from the episode
404 Media: Police Used Flock to Give a Man a Traffic Ticket — https://www.404media.co/police-used-flock-to-give-a-man-a-traffic-ticket/
EFF: Traffic Violation! License Plate Reader Mission Creep Is Already Here — https://www.eff.org/deeplinks/2026/03/traffic-violation-license-plate-reader-mission-creep-already-here
DeFlock — https://deflock.org/
404 Media: Cities Are Ditching Flock, Immediately Replacing It With Axon License Plate Readers — https://www.404media.co/cities-are-ditching-flock-immediately-replacing-it-with-axon-license-plate-readers/
404 Media: Flock Pitched a Plan To Turn Uber and Lyft Drivers Into Roaming Surveillance Vehicles — https://www.404media.co/flock-pitched-a-plan-to-turn-uber-and-lyft-drivers-into-roaming-surveillance-vehicles/
The Conversation: New tech adds phone tracking to license plate readers — https://theconversation.com/new-tech-adds-phone-tracking-to-license-plate-readers-associating-devices-with-identifiable-cars-288876
Quote from this week’s episode
The issue is the system was there to make the mistake.
— Kevin Tackett
Tom’s take
The lesson here is not that every use of an ALPR system is automatically malicious. The lesson is that communities should not approve powerful surveillance infrastructure based only on the best-case story. If the system can be searched, shared, retained, expanded, or repurposed, then the rules need to be specific, public, enforceable, and audited.
Help Review The Digital Legacy Tree
(upcoming book by co-host Scott Wright)
Scott Wright is looking for a small group of volunteer beta readers to review the nearly finished manuscript of his upcoming book, The Digital Legacy Tree.
The book is a practical guide to helping your loved ones find, access, and understand the digital accounts, devices, documents, and information they may need when you're no longer able to manage them yourself. The manuscript is about 30,000 words and is planned for publication in September.
You don't need to be a cybersecurity expert. In fact, Scott is especially interested in feedback from ordinary people with real digital lives. If you've ever wondered whether your family could locate the information they would need during an emergency, illness, incapacity, or after your death, your perspective would be valuable.
Reviewing the manuscript is designed to be quick and easy using a simple online tool that allows you to highlight passages and record your reactions, thoughts, and comments as you read. A couple of hours of your time could help make the book significantly more useful for future readers.
Beta reviewers who provide meaningful feedback will:
• Be eligible for acknowledgement in the book's beta reviewer section
• Receive early access to companion resources, templates, and worksheets
• Receive a complimentary PDF copy of the finished book upon publication
Scott is hoping to recruit approximately 5–10 reviewers for this final round of feedback.
To volunteer, share your story, or suggest ideas that may help others facing digital legacy challenges, visit:
https://securityperspectives.com/digital-legacy-tools
Also worth your attention this week
Crooks are buying expired domains and using them to deliver malware. Old domains from abandoned campaigns, rebrands, side projects, or acquisitions can become someone else’s phishing and malware infrastructure if they still have trust, backlinks, or brand recognition. Inventory domains, keep auto-renew on important names, and retire links cleanly. Source: Security Affairs — https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html
AI-generated vacation photos are becoming scam bait. The Guardian covered scammers using AI holiday imagery on Instagram and Facebook to make fake travel offers look more credible. Do not treat polished photos, social engagement, or “looks real” as verification. Check the company, payment path, reviews, domain age, and whether the offer exists outside the ad. Source: The Guardian — https://www.theguardian.com/money/2026/aug/16/scam-ai-holiday-photos-instagram-facebook
Anthropic is watermarking Claude-generated text for EU law. AI provenance sounds helpful, but text watermarking raises hard questions about false positives, paraphrasing, detector control, and whether disclosure proves anything about authorship or trustworthiness. Watch this as AI transparency rules move from policy talk into product behavior. Source: Engadget — https://www.engadget.com/2237691/anthropic-watermarking-text-generated-by-claude/
Listen / Watch
🎧 Audio Podcast: https://sharedsecurity.net/2026/08/17/flock-cameras-exposed-traffic-tickets-alprs-and-vehicle-surveillance/
▶️ YouTube Version: https://youtu.be/mSnQE33WRVE
We’d love your feedback
Have you seen Flock cameras or other license plate readers in your city, neighborhood, school district, HOA, or shopping center? Do you know what the policy says about retention, sharing, audits, warrants, traffic enforcement, or immigration enforcement? Reply and tell us what you’re seeing locally.
Thank you to our sponsors!
Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.
🎁 Get 10% off your order of high quality faraday products built to protect your privacy from SLNT! Visit: https://slnt.com and use discount code "sharedsecurity" at checkout.
Closing
If you found this episode useful, subscribe to Shared Security, share it with someone that’s concerned about Flock cameras, and consider supporting the show through YouTube channel membership or by following us wherever you get your podcasts.
Stay safe, stay secure, and stay private.
Tom Eston
Founder and Host, Shared Security Podcast

