Abuse Is Guaranteed: A Cybersecurity Threat Model for Flock
- Rich Washburn

- 10 hours ago
- 18 min read


A Cybersecurity Threat Model for Flock — and Why I Can't Believe We Built This First and Started Asking Questions Later
I've been avoiding writing about Flock.
Seriously.
People know my background, so this comes up. I've spent more than three decades around technology, cybersecurity and digital forensics. Somebody sees one of these cameras, somebody mentions Flock, and sooner or later I get the question: "Rich, what do you think about this?"
And I've basically treated it like a third rail.
Not because I didn't have an opinion.
Because I had too many of them.
Then I saw one image of how this thing actually works.
And something clicked.
Maybe that's because I'm a visual guy. Maybe I just needed to see the architecture instead of hearing the sales pitch.
But once you see it as a system, there's a problem you can't unsee.
I've learned one occupationally unfortunate thing from cybersecurity: eventually, you stop evaluating technology according to what somebody says it's for.
You start asking what the architecture makes possible.
That's usually where all the fun ends.
So I finally stopped looking at Flock as a political issue.
I started threat-modeling it.
And, well... are you fucking kidding me?
Let's start with the strongest argument for Flock.
Not the dumb argument.
Not: "If you're not doing anything wrong, you don't have anything to worry about."
That one can go directly in the trash.
The strongest argument for Flock is a kidnapped child.
A child disappears. Police know the vehicle. An AMBER Alert goes out. A camera recognizes the plate. Within minutes, cops know where that vehicle was seen. The child comes home.
That's not theoretical.
Flock says its work with the National Center for Missing & Exploited Children has contributed to the recovery of more than 100 missing children since 2021, and NCMEC has publicly discussed the usefulness of automated license-plate readers in missing-child cases.
Good. No sarcasm. Good.
If the number were one, I'd still say the technology clearly has value.
If that were my kid, I'd probably want a camera hanging from every telephone pole in America.
I understand the argument. Keep that capability. Absolutely.
Now explain to me why finding that child requires building infrastructure capable of reconstructing everybody else's movements.
Because those are two completely different engineering requirements.
And that's where I start calling bullshit.
Somewhere along the way, we apparently accepted this weird premise: if one legitimate use of mass collection exists, then mass collection must be the necessary architecture.
No.
That's not how engineering works. That's how convenient engineering works.
Let's assume Flock is populated entirely by saints.
Let's make this ridiculously easy for them.
Everyone at Flock is wonderful. Every executive wakes up thinking about kidnapped children and stolen cars. Nobody has an agenda. Nobody gives a shit where you went last Tuesday. Nobody wants to monetize anything they shouldn't. Nobody ever gets greedy. Nobody ever gets promoted into a job they shouldn't have. Nobody's bonus ever depends on expanding the network. Nobody ever gets acquired. Nobody ever gets pressured by a government customer. Nobody ever decides that today's "absolutely not" is tomorrow's "strategic partnership." Everybody involved is just walking around saving puppies and helping old ladies across the street.
Sure. Totally. Let's give them all of it.
My eyebrow is somewhere near my hairline, but fine.
It still doesn't matter.
That's the part I don't think people understand.
Cybersecurity doesn't work by evaluating the moral character of the current system owner.
Nobody reviewing a network says: "Dave has root access, but Dave seems like a really nice guy."
That's not a control.
You ask: Who can access this? What can they do? How are they authenticated? What gets recorded? Who can change the logs? What happens if credentials are stolen? What happens if an insider goes bad? What happens if a trusted user's kid grabs his laptop? What happens when some teenager finds something nobody noticed? What happens when a vendor gets compromised? What happens when a government changes policy? What happens when a company gets acquired? What happens when somebody plugs this dataset into an analytical system that didn't exist when the data was collected? What happens when an attacker gets the same AI tools the defender has?
That's not cynicism. That's Tuesday.
ABUSE IS GUARANTEED.
And here's the funny part. I don't even have to argue that somebody will abuse Flock.
We're past that. They already have.
A Washington Post investigation found at least 50 law-enforcement officers had been charged with or accused of abusing automated license-plate-reader systems, and Flock was involved in 46 of those cases.
One Florida officer is accused of querying Flock 717 times to follow his estranged wife's vehicle.
Seven hundred and seventeen.
Apparently one or two would've been too subtle.
Investigators allege he selected supposed law-enforcement reasons for some of those searches even though his wife wasn't part of those investigations.
Other cases have involved wives, girlfriends, ex-girlfriends, romantic interests, coworkers, personal grudges — the exact human behavior anybody who's spent five minutes around privileged databases would've predicted.
So let's retire this sentence: "Someone could theoretically misuse it."
No. Someone does misuse it.
The real question is: how much of the misuse are we actually catching?
Because that's a much uglier question.
An audit trail is wonderful once somebody knows to inspect the audit trail. It doesn't magically tell the woman being followed by her ex: "Hey, by the way, somebody just searched your car for the 318th time."
Logging something isn't the same thing as preventing it.
Security people know this. Or we're supposed to.
The model behaved. The attack still worked.
I've written about this problem before in AI security.
We tend to look for the big dramatic failure. Authentication bypassed. Encryption cracked. Malware installed. Model jailbroken. Root shell obtained.
But some of the most dangerous modern systems failures happen when everything works exactly as designed.
The officer successfully authenticates. The account is valid. The system accepts the query. The database correctly finds the plate. The result comes back. The audit log records the transaction.
Beautiful. Congratulations. Every component behaved perfectly.
And somebody just used government surveillance infrastructure to stalk his wife.
That's what I meant when I wrote The Model Behaved. The Attack Still Worked.
Increasingly, the failure doesn't exist inside one component. It exists in the composition.
The authorization was legitimate. The intent wasn't. And if your system can't meaningfully distinguish those two things, you haven't solved the actual problem. You've authenticated the problem.
Then somebody steals the password.
Okay. Let's make it even easier.
Every cop is now perfect too. Nobody stalks anybody. Nobody gets curious. Nobody looks up their neighbor. Nobody checks where their girlfriend went.
Wonderful. We're still screwed.
In 2025, Sen. Ron Wyden and Rep. Raja Krishnamoorthi asked the Federal Trade Commission to investigate Flock's cybersecurity after their investigation found that passwords associated with at least 35 Flock customer accounts had reportedly been stolen through infostealer malware.
They also cited evidence that appeared to show Flock credentials offered on a Russian-language cybercrime forum.
Now, to be precise: I haven't found evidence that somebody used those credentials to dump America's vehicle movements. Flock says its core platform hasn't suffered a giant breach, and I haven't found credible evidence proving otherwise.
Fine.
But again, that's not the important part. The credentials escaped. That's the event. That's the attack path.
The defense seems to become: "But nobody drove the truck through the open gate."
Okay. Why was the gate open?
And at that time, universal multifactor authentication wasn't mandatory.
We're talking about accounts touching a system capable of searching physical movement. This isn't Disney Plus.
How in God's name did we get all the way to national-scale deployment before we were arguing about mandatory MFA?
That's where the whole thing starts making me crazy.
Because none of this is advanced.
Nobody slapped the table?
That's really the subtext of this entire article. How did this get this far?
At some point, somebody had to draw the architecture. Somebody had to say: "So we're going to put cameras all over the country." Yep. "And they're going to identify vehicles." Yep. "And timestamp them." Yep. "And retain those observations." Yep. "And police departments will be able to search them." Yep. "And agencies can participate in broader sharing networks." Yep. "And eventually we'll integrate more records, more sensors, live video, analytics and drones." Yep. "And tens of thousands of human beings will get privileged access to pieces of this." Yep. "And these records concern people who haven't necessarily committed any crime." Yep.
And nobody in the fucking room stood up and said: "Hang on. What the hell are we building?"
Nobody? Nobody slapped the whiteboard marker out of somebody's hand? Nobody said: "Before we deploy this everywhere, perhaps the privacy architecture should be as mature as the surveillance architecture?"
Instead, we apparently built the capability first and started having the national argument afterward.
That's backwards. Completely backwards.
And maybe that's the part that bothers me most. We're debating safeguards after the thing exists. The default position has already flipped. Now anybody who wants restrictions has to explain why we should remove capability. That's much harder politically and commercially than requiring justification before creating the capability in the first place.
Classic ratchet.
If you can track Americans, prove who you are.
I'll make my own position easy.
I don't think ordinary username-and-password authentication is remotely sufficient for this class of system.
Hell, I don't think ordinary MFA is enough.
You're accessing infrastructure capable of tracking human movement? Great. Prove who the hell you are.
Hardware-backed credential. Phishing-resistant authentication. Biometric presence verification where legally and technically appropriate. Face. Palm. Something. I don't care which implementation survives proper security and civil-liberties review.
But I want the query cryptographically attributable to an actual human being.
Not a shared account name. Not "Rich logged me in." Not "everybody on the task force uses that account."
Absolutely not.
You touched the machine that tracks people. We know who touched it. Period.
And the audit record should live somewhere you can't quietly clean up later.
Then publish who used it.
Here's another place where I suspect I'm going to annoy everybody.
I don't necessarily want the public seeing the specific plate an officer searched at a specific time. If that's part of an active kidnapping, murder or organized-crime investigation, obviously there are legitimate reasons to protect details.
But I absolutely want the public able to know that an officer accessed the surveillance system at a given time.
Those are different things. One reveals an investigative target. The other reveals the exercise of government power. And those shouldn't automatically be treated as the same category of secrecy.
If you're exercising surveillance authority on behalf of the state, I think your exercise of that authority should leave a publicly visible footprint. Agency. Named authorized user. Timestamp. Type of access. Local or cross-jurisdictional. Whether a valid case authorization existed. Maybe whether it was an emergency exception.
That's it. No target required. No victim's identity. No investigative secret. Just: these are the human beings who used this capability today.
Flock already says searches are logged. Good. Take the next step.
If government is using the system, transparency shouldn't be a product feature somebody can toggle. It should be law.
And yes, misuse should hurt.
Using something like this to track an ex shouldn't be an HR problem. I'm sorry. That's insane.
If you knowingly use government surveillance infrastructure to track somebody for personal purposes, I don't want a written reprimand. I don't want suspended database access. I don't want retraining.
I want consequences. Serious ones. Criminal exposure where intent and conduct warrant it. Potential felony-level penalties. Loss of certification. Permanent loss of access to privileged investigative databases. Civil liability. And consequences for supervisors who knowingly allow credential sharing or other deliberate circumvention.
Why? Not because law-enforcement officers are uniquely bad. Because humans are humans. That's the entire premise of security. We don't install locks because everybody is evil. We install locks because eventually somebody isn't trustworthy. The more powerful the capability, the stronger the lock and the uglier the penalty for deliberately defeating it.
HIPAA isn't a perfect analogy, but it's close enough to make the point. We've decided medical information deserves special handling. Great. Location intelligence deserves at least that degree of seriousness. Maybe more.
Your medical chart tells somebody what happened inside the doctor's office. A sufficiently capable movement system tells somebody you went there. And maybe who you met afterward. And where you slept. And what church you attended Sunday. And whether your car keeps appearing outside a particular political organization.
Tell me again why this deserves ordinary database security.
The kidnapped child does not require the current architecture.
Here's where I think the entire "privacy versus safety" argument starts falling apart.
Let's take Flock's strongest case. Abducted child. Known plate. Urgent threat. We want national-scale detection immediately.
Fine. Send a cryptographically signed alert package to edge cameras. Look for a specific plate. Camera sees a match? Transmit the minimum necessary evidence. Location. Timestamp. Supporting image. Dispatch police. Camera sees anything else? No lawful target? Discard it.
Maybe there's a short encrypted rolling buffer for genuinely exceptional circumstances. Maybe retrospective access requires a second independent authorization. Maybe crossing jurisdictional boundaries requires another token. Maybe nationwide searches require a warrant or statutorily defined emergency condition. Maybe two people have to approve some classes of searches. Maybe the edge hardware does far more of the matching so innocent observations don't need to become centrally queryable records in the first place. Maybe expiration is cryptographic instead of contractual.
None of that is magic. We know how to do this stuff. Hardware security exists. Zero trust exists. Threshold authorization exists. Federated computation exists. Modern cryptography exists. Immutable logs exist. Privacy-preserving architectures exist.
So when somebody tells me this is just what the system has to look like if you want to find kidnapped kids... no. Calling bullshit.
That's a design choice. It may be a commercially convenient design choice. It may be an operationally efficient design choice. It may even be the easiest design choice. But don't tell me it's the only engineering choice. It isn't.
The fact that the alternatives are obvious is itself information.
This is the thing I've been chewing on.
If protecting privacy required some breakthrough in theoretical mathematics nobody had invented yet, I'd have more sympathy. But we're talking about basic principles. Least privilege. Data minimization. Strong identity. Short retention. Independent authorization. Immutable logging. Purpose limitation. Segmentation. Explicit federation boundaries. Behavioral anomaly detection.
Come on. These aren't 2040 technologies. These are security architecture fundamentals.
So when I see the scale of the national fight required to impose controls that feel this obvious, I learn something. Not necessarily that Flock is secretly evil. I don't have evidence for that. But I learn that the incentives around this capability aren't naturally aligned with minimizing it.
Of course they're not. A surveillance network becomes more useful as it gets bigger. More cameras. More jurisdictions. More data. More integrations. More historical context. More searchability. More users. More analytics.
Privacy generally wants exactly the opposite. Less collection. Less retention. Smaller scopes. Harder access. Fewer relationships. Less federation.
Those two optimization functions are naturally in tension. No Bond villain required. That's enough.
This is Pokémon GO all over again.
Years ago I wrote about Pokémon GO and the mistake people make when judging technology by the cute application sitting on top of it.
The Pokémon were almost beside the point. The architecture was interesting. Location. Phones. Cameras. Mapping. Human behavior. Millions of people voluntarily carrying sensors everywhere.
The better question was never "what's this app for?" The better question was: what does this architecture make possible?
I'm asking exactly the same question now.
Don't tell me what Flock calls the product. Don't tell me which crime was solved last week. Show me the architecture.
Distributed sensors. Vehicle identification. Timestamped physical observations. Searchable history. Cross-agency sharing. Investigative records. Computer vision. Live video. Identity correlation. Drones. Analytics.
Put all of that on one whiteboard. Now step back ten feet. What did we build?
Because at some point "license-plate reader" becomes an almost comically inadequate description. It's like calling AWS "a website host." Technically, sure. But you've missed the point.
Storage topology isn't the privacy boundary.
Here's another one I keep hearing. "The local agency owns the data." Okay. "The data isn't sitting in one giant federal database." Great. "Agencies choose what they share." Wonderful.
All relevant facts. Still not enough.
If I can search distributed datasets as though they're one environment, telling me the bits technically live in different places doesn't magically make me feel better.
Storage topology isn't the privacy boundary. Query topology is.
The citizen doesn't care whether his plate observation was physically stored in Fort Lauderdale, Atlanta, or some cloud region. The citizen cares that somebody typed his information into a screen and reconstructed where he went.
Federation can give you many of the capabilities of centralization without the PR problem of calling it a centralized database.
Again, I'm not saying that's some sneaky plot. I'm saying that's what distributed systems do.
VENONA already taught us this.
I've written about "Harvest Now, Decrypt Later." The bigger lesson from VENONA wasn't just encryption. It was that information can outlive the assumptions under which it was collected. Something boring today becomes incredibly revealing tomorrow. Something expensive to analyze today becomes trivial later.
Now, Flock isn't claiming it stores every plate forever. That's important. Don't distort the analogy.
The lesson is different: never evaluate collected data solely against today's ability to exploit it.
Yesterday, correlating tens of thousands of observations required a bunch of analysts. Tomorrow: "Show me every vehicle that repeatedly co-locates with this one. Identify likely home and work locations. Infer relationships. Highlight changes in routine. Rank associated people by confidence." Done. Maybe before lunch. Probably before you've finished saying the prompt.
That's what AI does to data. It changes the economic threshold of analysis. Information that was technically available but practically useless suddenly becomes practically useful. That's capability expansion without collecting one additional byte.
The Horde is at the Wall.
Then there's the attacker.
For most of computing history, human effort acted like a hidden security control. Finding weird endpoints took time. Enumerating infrastructure took time. Testing thousands of possibilities took time. Reading documentation took time. Correlating tiny clues took time. Humans got tired. Humans got bored. Humans went to sleep.
Agents don't.
I've written about this as The Horde at the Wall. Modern AI can enumerate, probe, correlate, retry, analyze and write tooling at machine scale.
So I don't care if Flock hires brilliant security engineers. I hope they do. I don't care if they have great penetration testers. They should. I don't care if they take cybersecurity incredibly seriously. Fantastic.
Eventually, somebody finds something. That's not an insult to Flock. That's software.
Hell, Flock's own leadership has effectively acknowledged the obvious: no company is infallible or unhackable.
Exactly. Thank you. We're in agreement.
Now explain why we're comfortable building national surveillance capability whose acceptable operating condition depends on unauthorized access never happening.
Because that's the part that makes no sense.
Maybe some fifteen-year-old does it by accident.
And this is where Abstracted Magic comes in.
Twenty years ago, doing something truly nasty to a sophisticated surveillance system probably required a sophisticated operator. Today? Less so. Five years from now? God knows.
Maybe it's a foreign intelligence service. Maybe it's organized crime. Maybe it's a contractor. Maybe it's an angry employee. Maybe it's some kid who asks an AI agent the wrong question and suddenly discovers that something everybody assumed was difficult isn't difficult anymore.
That's abstraction. We keep wrapping extraordinary capability in simpler interfaces. That's fantastic when we're trying to help humans create. It's horrifying when we're lowering the expertise required to exploit.
The machine doesn't know whether the intent behind "find every system that exposes this endpoint and correlate the results" belongs to a researcher or an attacker.
Capability is capability.
And nobody gets to promise me the future.
This might be the simplest part.
I don't care whether I trust Flock's current CEO. I don't care whether I trust today's police chief. I don't care whether I like today's president. None of them owns the future.
Companies get acquired. Founders leave. Boards change. Investors change. Markets change. Contracts change. Terms of service change. Police chiefs retire. Attorneys general get elected. Presidents change. Wars happen. Emergencies happen. Laws expand. Exceptions become policy. Temporary measures become permanent infrastructure.
And twenty years later somebody looks at the thing and says: "Well, obviously we need it. We've always had it."
No. We didn't. Somebody decided to build it.
And that's why you don't design civil infrastructure around the personality of the person currently holding the keys.
Give the keys to the person you hate.
This should be the test for every government surveillance capability.
Think about the politician you trust most. Forget that person. Now think about the politician you distrust most in the country. That one. The person who makes you irrationally angry just seeing their face.
Now give them the surveillance system. Give their appointees access. Give their attorney general access. Give their preferred federal agencies access. Give them their definition of national security. Their interpretation of public safety. Their version of an emergency. Their political enemies.
Still comfortable?
Perfect. Now we're finally threat-modeling. Because that's how you design durable limits on government power.
You don't build the system for George Washington. You build it so it's tolerable under King George.
I don't want people tearing the cameras down.
This needs to be explicit.
Don't vandalize Flock cameras. Don't cut them down. Don't destroy public or private property. Besides being illegal, it solves nothing. We'd still have exactly the same policy and architectural problem afterward.
And I'm not arguing that society should throw away technology capable of finding abducted children, locating dangerous fugitives or identifying vehicles connected to serious crimes. That's stupid.
I want the harder thing: build the version we can safely keep.
Because this version? No. I don't believe this architecture, in its current form, has earned this degree of public trust. And I don't believe the institutions currently exercising access have demonstrated that they should receive such sweeping capability with controls this immature.
That's not anti-police. If anything, competent police departments should be demanding stronger controls. Because every idiot who uses this thing to stalk his girlfriend damages public confidence in every legitimate search that follows.
My minimum requirements aren't subtle.
If automated physical-location surveillance is going to exist in America, here's roughly where I'd start.
Every privileged user gets a unique, hardware-backed, phishing-resistant identity. High-risk access requires biometric or equivalent strong proof of physical user presence. Shared credentials are technically impossible. Every access event is immutably tied to a specific human being. Every search requires a valid statutory, case, warrant or emergency predicate. High-risk retrospective searches require independent approval. Nationwide or cross-jurisdictional searches are case-scoped exceptions, not routine capabilities. Retention defaults to the shortest technically useful period. Extending retention requires affirmative justification. Nonmatching observations are discarded wherever the legitimate use case allows. Sensitive audit logs are held in a way the querying agency can't quietly alter. Government-user access activity is publicly reportable without exposing active investigative targets. Deliberate misuse carries serious criminal, civil and professional consequences. Vendors operate under least privilege. Contractors operate under least privilege. Every outside integration is independently auditable. Every agency publicly discloses which networks it shares into and which agencies can search its sensors. Emergency exceptions automatically trigger independent review. Citizens have a mechanism for notification and remedy when improper surveillance is discovered. Security researchers have meaningful legal safe harbor for responsible testing. Federal agencies can't quietly piggyback on local credentials. Material expansions in capability require public approval, not an invisible software update. Every new feature is threat-modeled against the assumption that a future operator is hostile.
None of this is radical. That's the point. None of this is radical.
Which makes me ask again: how did we get here without it?
That's my real problem with Flock.
Not that it has no value. It does. Not that everyone working there is evil. Obviously not. Not that every cop is going to abuse it. They're not. Not that Flock definitely gets catastrophically hacked tomorrow. I have no evidence of that.
My problem is more basic. This thing got all the way to national-scale infrastructure before society appears to have seriously answered the first-order architectural questions.
That's nuts. The controls are catching up to the capability. They should've preceded it.
Flock is now rolling out stronger restrictions, shorter default retention, better misuse detection, stronger authentication and other guardrails. Great. I'm glad. But that doesn't make me feel better about how we got here. It makes me wonder why a company entrusted with something this consequential apparently needed real-world abuse, congressional scrutiny and national backlash to arrive at controls a security architect could've scribbled onto a napkin before lunch.
That's not the maturity curve I want attached to population-scale surveillance.
Move fast and break things is one thing when you're launching a photo-sharing app. The thing being broken here is privacy. Different tolerance.
Don't make morality a security control.
That's probably the most useful thing cybersecurity ever taught me.
People think working in security makes you cynical. They're right. Eventually you stop trusting devices. You read permissions. You wonder where the logs go. You see a camera and immediately want to know what network it's on. You hear "authorized users only" and immediately become interested in the authorized users. You hear "we don't share the data" and start reading the contract. You hear "the customer owns the data" and ask who controls the encryption keys.
It's a horrible way to live. I strongly recommend accounting.
But underneath all of that occupational paranoia is a very boring lesson: never make morality a security control.
Good intentions aren't authentication. Policies aren't authorization. Corporate values aren't encryption. Training isn't least privilege. A privacy statement isn't deletion. Logging isn't prevention. Compliance isn't security. "We would never do that" isn't architecture. And "you can trust us" isn't a threat model.
So I don't need to prove Flock is evil. Actually, the argument gets stronger if I assume exactly the opposite.
Let's assume Flock is wonderful. Let's assume its leadership means every word. Let's assume every current customer is acting in good faith.
Then ask the only question that matters: why would we build a system whose safety requires all of those things to remain true forever?
We already know trusted people abuse surveillance access. They have. We already know credentials escape. They have. We already know software contains vulnerabilities. It does. We already know analytical capabilities improve. They're improving at an absurd rate. We already know corporations change. Governments change. Policies change. People change. And attackers don't give a shit what your mission statement says.
So no, this isn't a left-wing argument. It isn't a right-wing argument. It isn't anti-police. It isn't anti-technology. It isn't even really anti-Flock.
It's a systems argument.
It's the question cybersecurity keeps forcing us to ask after everybody else has moved on to the demo: what happens when this gets used exactly the way we hope it won't?
Because eventually, it will.
It already has.
ABUSE IS GUARANTEED.
The only responsible question left is whether we finally design accordingly.
Sources & Further Reading
Flock Safety / National Center for Missing & Exploited ChildrenFlock says its partnership with NCMEC has contributed to the recovery of more than 100 children nationwide since the partnership began in 2021.https://www.flocksafety.com/blog/how-ncmec-and-flock-safety-bring-missing-children-home
The Washington Post — “How rogue officers turned a nationwide camera network into a tool for stalking”Investigation identifying at least 50 law-enforcement officers charged with or accused of abusing automated license-plate-reader systems; Flock was used in 46 of the cases examined.https://www.washingtonpost.com/technology/2026/08/02/how-police-officers-used-vast-network-cameras-spy-their-exes/
Sen. Ron Wyden / Rep. Raja Krishnamoorthi — Request for FTC Investigation of Flock SafetyCongressional investigation citing passwords associated with at least 35 Flock customer accounts reportedly stolen by hackers, along with concerns about authentication and access controls.https://www.wyden.senate.gov/news/press-releases/wyden-krishnamoorthi-urge-ftc-to-investigate-surveillance-tech-company-on-negligently-handling-americans-personal-data
Flock Safety — Privacy, Accountability, Security and Transparency SafeguardsFlock’s August 2026 announcement covering shorter default retention, mandatory misuse detection, stronger account controls and additional auditing and transparency measures.https://www.flocksafety.com/blog/flock-guardrails-address-lpr-privacy-concerns-and-police-transparency
Flock Safety — Products / FlockOSFlock’s own description of its broader platform integrating cameras, video, investigative software, real-time operations and other public-safety technologies.https://www.flocksafety.com/products
Prior Work
Harvest Now, Decrypt Later: What VENONA Already ProvedWhy information must be evaluated against what future technology may make possible — not merely what can be extracted from it today.https://www.richwashburn.com/post/harvest-now-decrypt-later-what-venona-already-proved
I Told You Not to Bring Pokémon GO Near My OfficeThe underlying question for any technology: What does the architecture make possible?https://www.richwashburn.com/post/i-told-you-not-to-bring-pok%C3%A9mon-go-near-my-office
The Pattern, Part II: It’s Not the Models. It’s the Shared Testing Vendor.How trust relationships and shared infrastructure become attack paths.https://www.richwashburn.com/post/the-pattern-part-ii-it-s-not-the-models-it-s-the-shared-testing-vendor
The Horde Is at the WallWhy automation and AI are destroying the human-effort assumptions that quietly protected systems for decades.https://www.richwashburn.com/post/the-horde-is-at-the-wall
The Model Behaved. The Attack Still Worked.Why every individual component can operate correctly while the larger system still produces a catastrophic security failure.https://www.richwashburn.com/post/the-model-behaved-the-attack-still-worked
Abstracted MagicHow increasingly powerful abstractions lower the expertise required to wield — and misuse — sophisticated technology.https://www.richwashburn.com/post/abstracted-magic
Rich Washburn is a technologist, strategist, and Founder & Chief AI Architect of ARIA AI Labs, working at the intersection of AI, infrastructure, communications, and capital. He also serves as Managing Partner and Chief AI Officer at Eliakim Capital.





Comments