At the September 2 City Council meeting, the Suffolk Police Department gave a lengthy presentation defending its use of automated license plate readers and other surveillance technology. I want to make something clear at the outset: I do not believe the officers giving this presentation were intentionally misleading City Council or the public.
I think they believe what they told us.
The problem is that they are law enforcement experts, not software engineers. They understand Flock from the perspective of an end user. They know what an officer sees when they log in, what fields an officer has to fill out, what their department policy says, and how Flock has been useful in criminal investigations. What they did not demonstrate is an understanding of the system as a large, interconnected software and data-security platform.
That distinction matters to me. I am a software engineer. I have worked on highly secure systems involving nuclear naval construction, personal financial information, and life insurance data. In those environments, we do not consider a system secure simply because it has a login page, multi-factor authentication, an audit log, and a policy telling employees not to abuse it. Those are useful controls, but they are only pieces of a much larger security model.
The presentation demonstrated over and over again that Suffolk is looking at Flock primarily through the lens Flock itself has given them, and some of the assurances they gave City Council simply do not hold up under scrutiny.
“No one can access our data except for us.”
Major Jesse Epperson made perhaps the most striking statement of the entire presentation while discussing Suffolk’s ownership of its ALPR data:
“No one can access that data except for us.”
He then repeated it. He also stated that, under Virginia law, the vendor cannot access Suffolk’s data. That is not correct.
Virginia Code § 2.2-5517 specifically allows other law enforcement agencies to query an agency’s ALPR data when the statutory requirements are met. It also specifically allows the vendor to access system data and audit data, at the agency’s request, for maintenance and quality-assurance purposes. (law.lis.virginia.gov)
And Suffolk absolutely does allow other agencies to access its data.
Suffolk’s own Flock transparency portal lists a massive network of outside organizations with access. Depending on when the portal is checked, that number has been around 160 or more agencies. Suffolk’s own quarterly report to Virginia State Police likewise answers “YES” when asked whether other agencies are allowed to access its data and then spends pages identifying those agencies. (suffolkva.us)
Perhaps Major Epperson simply misspoke and meant that only Suffolk employees have Suffolk user accounts. That would be a very different claim, but it leads directly to a much more serious accountability problem.
Suffolk’s accountability ends at Suffolk’s borders. Its data does not.
Mayor Mike Duman correctly raised the concern that an officer could misuse this system to look for a girlfriend, boyfriend, spouse, or someone else they have no legitimate reason to track. He also emphasized that officers who misuse the system should face significant consequences.I agree completely. But Suffolk Police can only discipline Suffolk Police employees.
If an officer in another Virginia jurisdiction improperly searches Suffolk’s cameras, Suffolk cannot suspend that officer. Suffolk cannot fire them. Suffolk cannot conduct their employee discipline. Suffolk cannot take away their badge. At most, Suffolk can revoke access, notify that officer’s employer, and potentially refer criminal misuse for prosecution.
This is not a hypothetical concern. The Washington Post has documented dozens of officers accused of abusing ALPR systems, including officers accused of searching wives, girlfriends, ex-partners and other personal acquaintances. In Haines City, Florida, investigators found that an officer repeatedly searched his wife’s plate while entering reasons that made the searches appear connected to unrelated cases involving drugs, assault, theft and a wanted fugitive. (washingtonpost.com)
A security system is only as trustworthy as everyone inside its trust boundary. Suffolk has extended that boundary far beyond Suffolk.
Saying “we audit everything” does not tell us what an audit actually proves.
A huge part of SPD’s argument was auditing.
Major Epperson explained that he personally conducts an audit every month and that the process generally consumes much of a working day. He described checking search records against CAD and incident numbers to ensure that officers entered real cases.
That is good. Suffolk should be auditing this system.
But the presentation never answered the most important question:
What actually constitutes an audit failure?
Checking that case number 12345 really exists does not tell us whether the plate an officer searched had anything whatsoever to do with case 12345.
That is exactly how an officer could hide intentional abuse. The Florida case above is important precisely because the officer allegedly entered legitimate-looking criminal reasons while repeatedly searching his wife’s vehicle. The existence of an audit log did not magically make the searches legitimate. (washingtonpost.com)
So what does Suffolk do?
Does the auditor simply verify that the case number exists? Does he open the underlying investigative file and establish that the searched vehicle actually has a nexus to the case? Does he review every search? A random sample? Only searches flagged by software? What happens when something looks questionable? Is the officer interviewed? Is Internal Affairs notified? Has anyone ever failed one of these audits? The presentation never tells us.
Yet those are the questions that determine whether an audit is a meaningful safeguard or simply a paperwork check.
The sheer volume makes the audit process even harder to understand.
Suffolk’s Q1 report to Virginia State Police says its ALPR systems were queried 8,849 times in one quarter. (suffolkva.us)
That works out to roughly 2,950 queries per month.
Major Epperson said his monthly audit that day took approximately five and a half hours. If monthly query volume were similar to Q1, reviewing every individual query in that period would allow an average of about seven seconds per query.
Seven seconds.
And that assumes he does nothing else during those five and a half hours. No interruptions, no phone calls, no breaks, no reviewing user permissions, no examining manual hotlists, no looking at sharing settings, and none of the other tasks he indicated are part of the audit. There may be a completely reasonable explanation. Perhaps most of the audit is automated and only exceptions are manually reviewed. But if that is the case, then tell us that.
Because there is a very big difference between “every action is recorded in an audit log” and “every action receives meaningful human review.”
The first is only the technical capability of the system. The second is actual accountability.
The strongest automated safeguard has existed for only a few weeks.
This part of the presentation deserves far more attention than it received.
When Council Member Ebony Wright specifically asked what safeguards exist to prevent misuse, Major Epperson described a system that can detect atypical behavior, automatically lock an officer out, and require an administrator to manually restore access. Then he added that this feature had been rolled out “in the last couple of weeks.”
That means this safeguard did not exist for nearly all of Suffolk’s four-year history with Flock.
This is especially important because WIRED recently reported on Flock’s new “Audit Assistance” feature. According to WIRED, after one South Carolina sheriff’s office enabled it, an internal-affairs officer identified more than 2,700 allegedly unauthorized searches the following day. The tool can flag things like repeated searches of the same plate, searches limited to another agency’s cameras, and the same plate being searched under multiple case numbers. (wired.com)
This does not mean Suffolk has thousands of improper searches, but it does raise an obvious question.
SPD specifically told Council about its newly deployed automated safeguard. What did it find when they turned it on?
If it found nothing suspicious, that would be excellent evidence for SPD’s argument. Instead, we were told that the feature exists but nothing about its findings For a presentation built around accountability, that is a strange omission.
Mayor Duman said officers need probable cause. They do not.
Mayor Duman also stated during his comments that officers need probable cause to use the system. Virginia law does not say that.
Under § 2.2-5517, an ALPR system may be used as part of a criminal investigation where there is reasonable suspicion that a crime was committed, along with several other specified purposes such as missing-person and warrant investigations. Probable cause is a higher constitutional standard. (law.lis.virginia.gov)
More importantly, no individualized suspicion is required before Suffolk collects the original location record. The overwhelming majority of the vehicles photographed by Suffolk’s cameras are not suspected of anything at all. The tracking is done first. Suspicion and investigation comes later.
That is the fundamental privacy problem with Flock.
“No facial recognition” is true. It is also an incomplete description of what Flock can do.
SPD repeatedly emphasized that its license plate readers do not use facial recognition. On the narrow question of the ALPR cameras themselves, that appears to be true. But Flock’s technology has moved far beyond simply reading license plates.
Flock now sells a product called FreeForm that uses artificial intelligence to search enabled video feeds using plain-language descriptions of people. Flock itself gives examples such as “man in blue shirt and cowboy hat.” Its documentation says officers can search based on clothing and visible accessories, combine video results with LPR evidence, search shared cameras, and configure alerts when a person matching the description appears. Flock is careful to emphasize that this is not facial recognition. (flocksafety.com)
WIRED independently reconstructed Flock’s interface and found an AI-powered watch-list system capable of continuously searching cameras within a defined area for someone matching a written description. (wired.com)
To be clear, I have not seen evidence that Suffolk has enabled FreeForm’s people-search functionality. That is exactly the question City Council should be asking.
Because Suffolk is not merely operating isolated license plate cameras. Major Epperson told Council that the department uses FlockOS, where its various systems are managed together.
Suffolk’s own Real Time Crime Center page says that system integrates city cameras, privately shared cameras, LPRs, CAD records, records-management data, gunshot detection, body and in-car camera locations and streams, mapping and analytics, with drones listed as future development. (suffolkva.us)
Flock itself advertises FlockOS as a platform that unifies LPRs, video, drones, gunshot detection, CAD and other data, with features including cross-agency sharing, FreeForm search and alerts, event linking and the ability to “highlight movement.” (flocksafety.com)
When people talk about Flock, they often do so in the context of license plate readers, but FlockOS is purpose built to be a citywide data-fusion and surveillance platform.
Flock’s claim that it does not “track individuals” is mostly semantics.
Flock’s transparency messaging says it cannot track individuals. Technically, the roadside ALPR knows that plate ABC-123 was at location X at 9:14 a.m. It does not necessarily know the name of the driver. But in software and cybersecurity, removing someone’s name does not magically make data non-identifying.
Virginia law itself defines ALPR system data to include vehicle information together with the date, time and location at which the image was captured. The statute permits queries based on plates, vehicle characteristics, dates, times and locations. (law.lis.virginia.gov)
If I already know your license plate and can retrieve the places that vehicle has appeared, I can reconstruct part of that vehicle’s movement history.
Flock’s own marketing for FlockOS talks about highlighting movement, and one customer testimonial on its product page describes watching vehicles enter through LPR and then tracking them across the city. (flocksafety.com)
This isn’t GPS, meaning it’s not continuous, meter-by-meter tracking. But calling repeated timestamped location observations of the same vehicle “not tracking” is a semantic distinction that would sound very strange outside of a marketing department. With the number Flock cameras in Suffolk, it is nearly impossible to travel via car without having your location continuously recorded and updated. The police system knows when you’re near home, knows when you’re near work, near the grocery store, or near your church, even if it can’t narrow down the location of your vehicle to the exact inch.
Suffolk is collecting location information indiscriminately.
On September 3, Suffolk’s transparency portal reported more than 718,000 vehicle detections over the preceding 21 days, along with 515 search sessions and nearly 15,000 hotlist hits.
Those are vehicle detections, not 718,000 unique people. A single commuter may pass multiple cameras repeatedly, and visitors are included as well. But that actually illustrates the architecture of the system.
Flock may be targeted at the search stage. It is not targeted at the collection stage.
Hundreds of thousands of location observations are collected first so that a few hundred investigative search sessions can happen later.
There is no suspicion associated with nearly all of those detections. Someone drives to work. Someone visits a friend. Someone goes to a church, a political meeting, a doctor’s office, an addiction-treatment center or simply buys groceries.
The camera records the vehicle because the vehicle passed the camera. That is the system working exactly as designed.
SPD never really addressed the constitutional question.
I would not claim that the Supreme Court has already ruled Suffolk’s ALPR network unconstitutional. It has not.
But the constitutional question is becoming increasingly difficult to dismiss.
In United States v. Jones, the Supreme Court held that attaching and using a GPS tracker on a vehicle constituted a Fourth Amendment search. That case relied heavily on the government’s physical intrusion onto the vehicle, so an ALPR network is not legally identical. (law.cornell.edu)
But this June, the Supreme Court decided Chatrie v. United States, a Virginia case involving historical cellphone location data. The Court held that police conducted a Fourth Amendment search when they obtained a person’s location history from Google, and specifically rejected the argument that the data was unprotected simply because it covered only two hours or was held by a third party. (law.cornell.edu)
ALPR data is different from cellphone location data. It is less precise, usually observes a vehicle rather than a phone, and only records locations where cameras exist. But the underlying constitutional question should be obvious:
At what point does the government’s automated collection and reconstruction of a person’s public movements become a search?
SPD’s presentation never meaningfully engaged with that question.
The success stories show that Flock is useful. They do not show that it is effective enough to justify its scale.
SPD presented several real cases where these systems helped investigators, including stolen vehicles, an abducted child and homicide investigations.
I have no reason to doubt those stories. Flock is useful. That is not the same question as whether the current system is effective, whether it prevents crime, or whether its benefits justify its costs and privacy consequences.
Research funded by the National Institute of Justice has found real benefits in some areas, particularly stolen-vehicle recovery. But the broader evidence is much less dramatic. A 2021 study found that LPR-equipped patrols increased stolen-vehicle recoveries but did not increase arrests or produce a measurable deterrent effect on crime. (nij.ojp.gov) Another randomized study found no general or offense-specific deterrence from the tested LPR deployment. (nij.ojp.gov)
A study of a large fixed network found apparent improvements in auto-theft and robbery clearances, but those effects were not statistically significant after other factors were accounted for. The researchers specifically called for more work evaluating the full costs and benefits of large-scale deployment. (nij.ojp.gov)
That is a much more complicated picture than a slideshow of success stories. The city should tell us how many investigations Flock materially changed, how many vehicles were recovered, how many arrests resulted, how many cases would likely have been solved through other evidence anyway, how many officer hours were saved, and what the system costs taxpayers per year.
The presentation provided no serious cost-benefit analysis at all.
Calling the “280 cameras” claim misinformation is particularly frustrating.
The Mayor said he had heard claims that Suffolk had “280 some Flock cameras,” initially believed that meant 280 cameras mounted around the city, and then characterized that claim as misinformation because SPD has only about 90 fixed roadside LPR cameras.
If someone said Suffolk has 280 fixed roadside Flock cameras, then yes, that would be incorrect. But saying Suffolk operates hundreds of ALPR cameras is not misinformation. The presentation itself says the department has contracted for 90 fixed readers and 208 readers mounted in marked police vehicles.
More importantly, Suffolk’s own Q1 report to Virginia State Police reported 283 ALPR cameras. The state reporting instructions explicitly say the total includes readers mounted inside or on police vehicles. (suffolkva.us)
A camera does not stop being an automated license plate reader because somebody bolted it to a patrol car instead of a pole. There are legitimate constitutional and operational distinctions between fixed and mobile readers. But acting as though counting both categories together is “misinformation” is especially difficult to understand when Suffolk itself reports them that way to the Commonwealth.
Data ownership is not data security.
Another repeated reassurance is that Suffolk “owns” its data. That is true. Virginia law requires agency ownership of ALPR data. (law.lis.virginia.gov)
But ownership is about legal responsibility and control. It is not a security mechanism. Your bank owns its customer database. That does not tell you whether the database is secure.
What matters is who can access the information, how access is authenticated, how authorization works, what other systems it connects to, what vendor personnel can do, what happens when credentials are abused, what logs are reviewed, and whether the controls can actually stop misuse rather than merely record it afterward.
This is why pointing to multi-factor authentication also misses much of the concern. MFA is excellent protection against someone stealing an officer’s password. It does nothing when the person abusing the system is the officer who legitimately owns the account.
And “Flock has never been hacked” is much narrower than it sounds.
Flock’s transparency portal responds to concerns that Flock has been hacked by saying its cloud environment has never been breached. Maybe that is entirely true. But that is a very carefully worded claim, and it is not the same as saying Flock’s products have never had serious security vulnerabilities.
Published vulnerabilities affecting Flock hardware have included a hard-coded password in Flock LPR firmware, an unauthenticated administrative API affecting Falcon, Sparrow and Bravo devices that could allow remote code execution from the local network, embedded secrets, and a Bravo device shipping with Secure Boot disabled. One of those unauthenticated-access vulnerabilities received a CVSS score of 9.8, Critical. (avd.aquasec.com) (opencve.alliance.unm.edu)
Flock itself has also acknowledged an incident in which a cellular carrier configuration error temporarily placed some cameras’ diagnostic interfaces onto the public cellular network, making them discoverable through internet scanning services. Flock says this did not expose its cloud or allow attackers to modify recorded video, and says it added authentication and detection controls afterward. (flocksafety.com)
None of this proves Suffolk’s currently deployed cameras are vulnerable today. Vulnerabilities get patched. Products change. But it demonstrates why “our cloud has never been breached” is not a meaningful substitute for a real security assessment.
This is not an accusation against Suffolk Police.
I actually think Suffolk Police deserves credit for several things.
They were conducting monthly audits before Virginia required them. They require training. They use MFA. They require case information for searches. They retain ordinary ALPR data for only 21 days, as Virginia law now requires. They confirm alerts before enforcement action. And I believe the officers who gave this presentation genuinely care about preventing misuse.
None of that answers the bigger question.
The City of Suffolk has built a system that collects hundreds of thousands of vehicle-location observations every few weeks, shares access across a large statewide network, combines license plate information with an expanding Real Time Crime Center, relies heavily on software supplied and continuously updated by a private vendor, and now exists in an environment where that same vendor is rapidly adding artificial-intelligence search and alerting capabilities.
A system with that much power deserves more scrutiny than “we have an audit log and we have never caught anyone abusing it.”
In every highly secure software environment I have worked in, the first question is never simply “Can this system be useful?” Of course it can.
The questions are: What can it do? Who can access it? What happens when someone abuses that access? How would we know? How quickly would we know? Who independently verifies the answer? And does the benefit justify giving the system that power in the first place?
Suffolk Police spent nearly an hour telling City Council why Flock is useful.
Those are the questions they still have not answered.
