A Looming Fourth Amendment Crisis
Legal experts and federal courts have raised serious concerns that mass ALPR surveillance may violate the Fourth Amendment's protection against unreasonable searches.
The government's unrestrained power to assemble data that reveal private aspects of identity is susceptible to abuse. - Justice Sonia Sotomayor, United States v. Jones (2012)
Key Legal Precedents
United States v. Jones
Justice Sotomayor noted in her concurring opinion that GPS monitoring creates “a precise, comprehensive record of a person's public movements that reflects a wealth of detail about her familial, political, professional, religious, and sexual associations.” She warned that the government's “unrestrained power to assemble data that reveal private aspects of identity is susceptible to abuse” and may “alter the relationship between citizen and government in a way that is inimical to democratic society.”
Carpenter v. United States
The Court ruled that cell site location information requires a warrant, because tracking someone's movements over time violates Fourth Amendment protections. The Court recognized that while individuals may not have privacy in a single instance of being in public, they do have privacy in “the whole of their physical movements.”
Commonwealth v. McCarthy
“With enough cameras in enough locations, the historic location data from an ALPR system in Massachusetts would invade a reasonable expectation of privacy and would constitute a search for constitutional purposes.” The court found that 31 days of location tracking was sufficient to constitute a Fourth Amendment search.
The Norfolk Lawsuit: A Test Case for ALPR Networks
In February 2025, a federal judge ruled that a lawsuit challenging Norfolk, Virginia's 176 Flock cameras could proceed. Chief Judge Mark Davis wrote that “a reasonable person could believe that society's expectations, as laid out by the Court in Carpenter, are being violated by the Norfolk Flock system.”
Judge Davis noted that the complaint alleged facts “notably similar to those in Carpenter that the Supreme Court found to clearly violate society's expectation of privacy: law enforcement secretly monitoring and cataloguing the whole of tens of thousands of individual's movements over an extended period.”
The federal government has since filed a statement defending Norfolk's surveillance system, and the case is ongoing with a trial date in 2026.
What Courts Are Saying
Multiple judges have expressed concern about mass test ALPR surveillance:
The citizens of Norfolk may be concerned to learn the extent to which the Norfolk Police Department is tracking and maintaining a database of their every movement for 30 days. - Judge Jamilah LeCruise, Norfolk Circuit Court, 2024
Even if the system is not unconstitutional now, the need for warrants could change as more cameras are added. - Chief Judge Mark Davis, U.S. District Court, 2025
More than 30 cities and counties have canceled, suspended, or rejected Flock contracts over privacy concerns — including Austin, Texas; Denver, Colorado; Sedona, Arizona; Santa Cruz, California; and Cambridge, Massachusetts.
Documented Abuses of ALPR Systems
The power to track anyone, anytime, without oversight has led to widespread abuses across the country.
When officers have unfettered access to location tracking with no oversight, abuse follows.
Police Stalking and Harassment
- Sedgwick, Kansas
Police Chief Lee Nygaard used Flock cameras to track his ex-girlfriend 228 times. He resigned and was sentenced to 18 months probation.
- Georgia
A police chief was arrested for using ALPR systems to stalk and harass individuals.
This is a pattern, not a set of isolated incidents. When officers have unfettered access to location tracking with no oversight, abuse follows.
Targeting Reproductive Healthcare
- Texas · 2024–2025
A Texas sheriff searched the nationwide Flock database for a woman who had obtained an abortion. Court documents and Flock's own data contradicted claims that this was a “missing person” search — the search terms explicitly referenced abortion and reproductive healthcare. The sheriff later considered bringing criminal charges.
This incident demonstrates how ALPR networks can be weaponized against individuals exercising constitutionally protected rights.
False Positives and Wrongful Stops
- Aurora, Colorado
A family was held at gunpoint after an ALPR mistakenly matched their vehicle to a stolen motorcycle from out of state. Officers failed to verify the alert. The incident resulted in a $1.9 million settlement.
- Multiple jurisdictions
A 12-year-old child was handcuffed after an ALPR misread a license plate, leading to a wrongful stop.
Immigration Enforcement in Sanctuary Cities
- Westchester County, New York
Federal immigration officials accessed ALPR data despite the county's sanctuary status.
- Multiple jurisdictions
Local police have conducted searches on behalf of ICE agents, sometimes using vague search terms like “law enforcement” or “ICE ASSIST” to obscure the true purpose.
The ICE Connection
One of the most alarming aspects of Flock's surveillance network is the documented sharing of local data with federal immigration enforcement. Often without local agencies' knowledge or consent.
What We Know About Federal Access
- August 2025 · The admission
After months of denials, Flock Safety admitted to running “pilot programs” with U.S. Customs and Border Protection (CBP) and Homeland Security Investigations (HSI). The company claimed to pause these programs amid mounting privacy concerns.
- The National Lookup Tool
75% of Flock's 7,000+ law enforcement customers have enrolled in the National Lookup Tool, which allows out-of-state agencies to access local data. Whether Bryan and College Station participate in this network is unclear.
- Default contract terms
Flock's standard agreement grants the company a “worldwide, perpetual, royalty-free” license to share customer data for “investigative purposes” — even if local departments think they have restricted access.
- Overseas data processing
December 2025 reports revealed that Flock uses workers in the Philippines to annotate surveillance data, raising serious concerns about data privacy and security.
Documented Federal Access Incidents
- Washington State · 2025
University of Washington research found that at least eight local law enforcement agencies had enabled direct sharing with Border Patrol. Ten more agencies had “back door” Border Patrol access to their data even though they had not explicitly authorized it.
- San Francisco · 2025
Out-of-state police ran more than 1.6 million illegal searches of San Francisco's Flock database, including at least 19 searches marked as related to ICE — in direct violation of California sanctuary laws.
- Illinois · 2025
Despite Illinois' sanctuary state status, Flock shared data with federal agencies. Illinois Secretary of State Alexi Giannoulias accused Flock of breaking state law.
- Colorado · 2025
After assuring the Loveland Police Department that federal agencies had no access, Flock admitted in November 2025 that Border Patrol had been given accounts with the ability to request access from local agencies. At least 25 Colorado departments agreed to share data.
Critical Cybersecurity Vulnerabilities
In November 2025, independent security researcher Jon Gaines (GainSec) published a comprehensive whitepaper documenting 51 vulnerabilities in Flock Safety's camera systems. The research, which has been submitted to MITRE for CVE assignment, reveals serious security weaknesses that raise concerns about data integrity, unauthorized access, and the reliability of evidence.
Device-Level Security Failures
Physical access vulnerabilities. Security researchers demonstrated that someone with physical access to a Flock camera can gain root-level control of the device. While cameras are mounted on utility poles in public locations, this access requires:
- Physically reaching the camera.
- Knowledge of specific button sequences, or use of USB devices.
- Time to perform the exploit — 30 seconds to several minutes, depending on the model.
Local data storage issues. Images captured by cameras are stored unencrypted on the local devices themselves. While Flock states that data transmitted to and stored in their cloud infrastructure is encrypted, the local storage vulnerability means:
- Anyone gaining physical access can extract unencrypted images.
- Local device integrity cannot be assured.
- Chain of custody for evidence may be compromised.
Exposed USB ports. Camera models have accessible USB-C ports that can be exploited with inexpensive tools to gain device control.
Software and Infrastructure Vulnerabilities
Outdated operating system. Cameras run Android 8.1.0 — an operating system discontinued in 2021 with no further security updates. This version has 64 documented critical vulnerabilities (CVEs) that will never be patched.
Hardcoded credentials (CVE-2025-47823). Security analysis revealed hardcoded passwords in the camera firmware, including:
- A Java Keystore file (
flock_rye.bks) bundled in the application. - The keystore password (
flockhibiki17) hardcoded in plaintext in the code. - Hardcoded WiFi network names the cameras will automatically connect to.
These cannot be changed by customers and represent permanent security weaknesses.
Network security concerns. During diagnostic and setup modes, researchers documented credentials transmitted in cleartext, creating opportunities for man-in-the-middle attacks under certain network conditions.
Authentication and Access Control Weaknesses
Multi-factor authentication is not mandatory. Until November 2024, Flock did not enable multi-factor authentication (MFA) by default. As of November 2025:
- MFA is now the default for new customers.
- 97% of existing law enforcement customers have enabled MFA.
- 3% of agencies — potentially dozens of departments — still rely solely on a username and password.
Stolen credentials in circulation:
- Police login credentials have been found for sale on Russian dark web forums.
- Hudson Rock, a cybersecurity firm, identified stolen Flock credentials in malware databases.
- In at least one documented case, the DEA used a stolen police officer's password to access Flock cameras without the officer's knowledge.
Evidence Integrity Concerns
With root access to local devices via physical compromise, an attacker could potentially:
- Modify locally stored images before they are uploaded.
- Delete specific captures from local storage.
- Install malware that alters future captures.
Federal and Expert Response
Congressional action. In November 2025, Senator Ron Wyden (D-OR) and Representative Raja Krishnamoorthi (D-IL) sent a formal letter to the Federal Trade Commission requesting an investigation into Flock Safety's cybersecurity practices. The lawmakers stated that the company's failure to require multi-factor authentication, combined with stolen credentials on the dark web, exposes the surveillance network to “hackers and spies.”
Flock's response. The company stated that the documented vulnerabilities “have no impact on our customers' ability to carry out their public safety objectives” and emphasized that physical access is required for device-level exploits. Flock continues to remediate findings through hardware and software updates.
Independent security assessment. The research has been formally documented and submitted to MITRE's CVE database, with disclosure windows extending through February 2026 as additional vulnerabilities are processed.