Right now, as you drive to Taco Bell to put some Diablo dusted chicken nuggets on your payment plan, a small black camera bolted to a pole is taking a picture of your license plate, running it through an ondevice neural network, and uploading the results to a nationwide searchable database where cops from across the country can find out everywhere you've been without needing a warrant. It's called Flock Safety, an $ 8.4 billion surveillance startup that went from catching package thieves in the Atlanta suburbs to building a real life Marauders map of every car in America. In today's video, we'll tear down how flock cameras actually work from the Edge ML pipeline to the cloud architecture. Then look at the 50-year-old legal exploit that makes the whole thing possible and find out how nerds are using war driving techniques from 2003 to surveil the surveillance. It is August 14th, 1984, and you're watching the code report. The Flock was founded in 2017 by an engineer named Garrett Langley who was frustrated that police wouldn't look into crimes in his neighborhood if they didn't have a license plate number. So he did what any of us would do and built a simple automated license plate reader and then sold it to the only organization willing to fund a surveillance state over some unpicked weeds homeowners associations. From there, Flock moved up market to police departments and today its cameras operate in thousands of communities, scanning billions of plates every month. The company even claims that its technology helps solve 20% of reported crime in America. A stat verified by the rigorous scientific method of massaging the data to fit into some Trust Me Bro benchmarks. Their flagship camera is called the Falcon. And from an engineering perspective, it's pretty clever. It's basically a 2017 era Android solar powered spy device with an LTE modem, infrared night vision, and a motion triggered camera that you can zip tie anywhere. But instead of streaming video to the cloud, the Falcon runs machine learning inference at the edge. When a car trips the motion sensor, an ondevice model captures stills, then builds what Flock calls a vehicle fingerprint by classifying the make, model, color, dents, rims, roof racks, and that baby on board sticker that tells the world you don't use Neoim. This is why the system still works when a plate is missing or covered because police can query for a Tesla Model 3 with a Ron Paul 2008 bumper sticker and get your car. Only the images and structured metadata get shipped over LTE to Flock Cloud, which keeps bandwidth low and the whole unit cheap enough to deploy by the thousands. From there, every car that drives by becomes a row in a database that is constantly compared against hot list for things like stolen vehicles and Amber Alerts. So, when a wanted car rolls past a camera, every cop in the area gets a push notification like a weird Orwellian game of Pokémon Go. But you don't get to an $8 billion valuation by selling a few cheap old Android boxes. What's really valuable is the data they've aggregated. Each scan on its own is just a plate with a time stamp. But with billions of scans stitched together, they know where you sleep, where you work, who you visit, and which parking lots you cry in. And because departments can opt into nationwide sharing, a deputy in a town of 300 people can query that history across all 50 states. Now, you're probably wondering how any of this is legal. And the answer is an unpatched exploit in the American legal system called the third party doctrine. In the 1970s, the Supreme Court ruled that once you voluntarily hand your data to a third party, you no longer have a reasonable expectation of privacy. So, the government doesn't need a warrant to get it. That was fine in the 70s, but today it creates a loophole where the government can circumvent the Fourth Amendment by subscribing to a SAS app where the dashboard is a dragnet. And the only thing standing between this database and abuse is an input field where cops write in the reason for their search. But, it turns out the honor system doesn't scale very well. Last year, an Idaho sheriff ran his wife's license plate more than 700 times in 3 months using test as his reason. An audit in Illinois caught local cops running searches for federal immigration agents with immigration as their reason. And a Kansas police chief ran his ex-girlfriend's plates 164 times and her new boyfriend 64 times. And I assume that wasn't for an Amber Alert. >> Stop it. Get some help. >> But the backlash is growing. Austin and Evston voted to rip their cameras out entirely. And a lawsuit in Virginia argues this is exactly the drag net the Fourth Amendment was supposed to prevent. But Flock doesn't seem too worried because it's busy expanding into gunshot detecting microphones, police drones, and an entire law enforcement operating system called Flock OS. It even had a partnership with Amazon Ring that would let cops request your doorbell footage through Flock's platform. That is until Ring ran a creepy Super Bowl ad about using AI to find lost dogs. And the backlash was so bad that they had to dump Flock within a week. But it's not all bad news because nerds are fighting fire with fire with a project called DFlock, an open- source data set that's already tracked down the location of tens of thousands of flock cameras across the country. It was started by a software engineer named Will Freeman after he noticed the cameras popping up all over Alabama and got annoyed that nobody could tell him where they were or who approved them. So, he built the map himself on top of Open Street Map and the open- source community did the rest. In fact, Flock was so impressed by this community effort that their lawyer sent Freeman a seasoned desist, for which he responded by saying, "No, it's comforting to know we have people out there still fighting the good fight, like Code Rabbit, the sponsor of today's video. They got tired of seeing me make new videos about new exploits hitting the timeline every week, so they just launched Code Rabbit Security to provide continuous code security that's powered by actual reasoning instead of brittle Regex rules. that their security agents are designed to think like an attacker in order to hunt for real vulnerabilities across your entire codebase. Then it prioritizes actual risks based on reachability, exploitability, and blast radius. And it explains the problem to you in plain English and suggests a fix you can approve and merge from the diff. The code rabbit security reviews every PR before merge and you can also schedule deep scans across your full codebase to protect your back door 24/7. Get 10 free code scans to try it out for free today at the link below. This has been the code report. Thanks for watching and I will see you in the next one.
Generated algorithmically for Search Engine
Indexing.