This is pure laziness aka “reduced time to market” on the part of Flock.
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false.
If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.
Exactly. It helps they also control who can even run for office in any meaningful way. Nobody fights the left harder than Democrats. Good luck finding a representative that is against data centers, flock, Israel, congressional stock bans and pausing and regulating AI, views overwhelming popular with the majority of the actual American public.
Funny. In my experience, nobody fights the “leftists” harder than the Democrats. I think the Republicans fight the Democrats harder than anyone else, and aside from the “leftists”, no political group seems to really fight the Republicans.
You are misunderstanding basic political terminology then, if you think it's somehow odd that leftists are against Democrats. Democrats and Republicans are both capitalists and liberal in the classical sense, both of which leftists oppose.
>Good luck finding a representative that is against data centers, flock, Israel, congressional stock bans and pausing and regulating AI, views overwhelming popular with the majority of the actual American public.
That is rapidly becoming Democratic party orthodoxy. At the very least there are a sizable number of Democrats who fit that.
Don't know why you're getting downvoted, but hackernews is very anti-democratic in nature. One thing politicians quickly realize, especially local ones, is that you do have to be accountable to voters at the end of the day. One or two bad stories is enough to sink a local race too, or at minimum require a massive spend to overcome the negativity.
Local politics is where you understand how effective a handful of people can truly be.
Happy to read people are understanding the true power they have collectively instead of as individuals.
It’s not laziness, it’s hyper focus on compliance. CJIS is the policy maintained by the FBI that handles information security, which is derived from standards built around paper.
Adding more weirdness, the details get worked out by each state.
My guess is they encrypted whatever is criminal justice information (license plate hotlists, etc) or protected by local laws (DMV data) and left the rest to make it easier to deploy and service. Remember pictures of you or your car taken in public are not protected or in scope.
Police tech is garbage and usually driven by federal grant spending. So it’s going to be interesting to see how Flock and Axon grow the business as it turns into a service model.
My problem is that Claude kept screaming across several sessions that it echo'ed a default password for a local, ephemeral development container into a session across SEVERAL sessions.
I get dinged continually for a vendor supplied container that writes an appropriately scoped access key to disk in plain text on startup (we are working to eliminate it but it requires migrating to an entirely new way of doing things the vendor only released earlier this year and I got derailed by other priorities).
So like if established enterprises using off the shelf scanning software are breathing down my back about this...what the actual hell is happening inside flock that this was fine. Lol.
Any breach of security on a system like this is a big flashing red-alert to me.
If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.
Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.
Getting persistent access to Flock's internal network is a high-priority item for every US adversary, who doesn't want free intel collection on the movements of persons of interest? Knowing who the FBI and local cops are monitoring in is the counter-counter-intelligence cherry on top of a self-inflicted dragnet surveillance cake.
Any entity with access to flock servers can virtually stake-out anyone/everyone driving past Flock camera to monitor their movements. In a hot war, this would provide actionable data to support assassination via road-side bomb/drone strikes.
That's why you or I would care, but that doesn't answer the question of why they would.
Large companies tend to be amoral. Unless it affects them monetarily (possibly indirectly) they're not going to care. Given what they do to make money, I don't see any of these things hurting them.
It's a red-alert to you and me, but Flock won't care. People already don't want these cameras in their cities, but police departments buy them anyway. What does it matter if there's one more reason you don't want them?
Apparently police are accessing the network via their personal devices. I highly doubt their security practices online are any better than this. I wouldn't be surprised either to see things that chinese manufacturers do such as intentional back doors.
Overall this goes from disappointing to fairly repugnant.
Allegedly you can buy credentials on the darkweb to perform national searches. Might explain why some of the logged reasons for recent searches were “LMAO”
The normal explanation is plenty, unless you’ve never met, read about, or heard anyone talk about, law enforcement officers (who are human beings - for better and for worse).
How many of us have had coworkers who put something like that into a commit message? And that's a message that's at least notionally supposed to be helpful to you or your coworkers, rather than existing purely for the purposes of oversight you don't want in the first place.
I would expect law enforcement coworkers to understand the law, department procedure, and public requests for their data. That’s expecting too much from the academy, I guess.
Those that fail to meet standards should be fired to spare the taxpayers from the lawsuits coming from AI-assisted complainants.
It’s also too much for Flock’s YC-funded technology to implement a field filter that rejects “LMAO” as a valid request.
At the very least, your local staff’s nationwide stalking credentials being harvested by phishing and abused by others should carry criminal negligence penalties. Governments should pass that liability onto this YC-funded startup company.
This meme will not die, and here you can see it blossoming into something even weirder.
There is one (1) case in the literature, back in the early 2000s, where a department rejected a candidate as overqualified based on a cognitive assessment; the rejected applicant took that department to court and lost.
That's it; that's all the evidence.
Against that: most police departments around the country administer written tests with general cognitive components for which there is a floor score and no ceiling (the POST, the NTN, &c). And virtually no departments --- none I'm aware of --- administer IQ tests.
From all this, we've now got "a federally protected right"?
Literally the only thing you know here is that one department didn't like one candidate and came up with a reason to deny him based on cognitive overperformance. For all you know, they didn't like his hair color, and came up with an excuse. And that's it: out of over 15,000 police departments in the US, almost 1,000,000 sworn officers, and over 25 years, this is the evidence you have for the claim that there's an enshrined "right" to reject police officer candidates who are "too intelligent".
It's an Internet urban myth. I'm just stepping in to call it out as such.
Many moons ago, I was involved in the technical side of volunteer work for domestic violence victims escaping abusive relationships with e.g. law enforcement (cops), who even fifteen years ago had sweeping powers to track and stalk their victims. Things like actual anonymous burner phones and the ability to e.g. create new email accounts without government identification were critical to the process of getting these people out safely, or alive, without fear of retaliation.
I can't even imagine how difficult this job must be nowadays, with bullshit like Flock spanning hundreds of police departments participating in their nationally-linked database. I have zero sources for what I'm about to say, but my instinct is that the political machines (expanding powers hidden behind "think of the children") behind how technology is evolving today has gotten people killed.
Quite potentially, yes. Their name is already mud among many voters, if they're shown to be treating data insecurely then that's another reason why local governments might consider terminating contracts with them.
They want the good, bad and ugly to flock to them as it were and vaporize them so Axon and Motorola Solutions can just pick up right where they left off. And people will just ignore or forget it because it's not the same company.
Is there any recent example of a company getting breached and its data exfiltrated, where the business was actually hurt? I predict we'll get a standard boilerplate "We take security very seriously" press release, a narrative that blames the evil hackers entirely and not the company's negligence, and then that will be that.
I really hate how Product Managers somehow get to take the reins of engineering teams instead of having to sell them product ideas.
It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.
Do you feel like an inadiquate imposter or something? I'm assuming you work in software.
Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design.
Or read about engineering failures like flight QF32 (mostly a success story):
A paperwork review showed that the required signatures were missing from 131 out of 138 retrospective concessions issued between 2009 and 2011
Australian Quantas, with a UK Rolls Royce engine on an Airbus, with engines maintained in Aussie.
Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems.
Certification matters less than you might think across international borders.
Perhaps I'm a cynic, but beliefs in certification seem so irrational to me. What is it? Jealous desires for status? Desire to have guilds/gatekeepers? Complete misunderstanding of how safety occurs in "real" engineering?
Your conclusion seems at odds with your evidence: the quote you reference indicates that a professional engineer was meant to examine the 'retrospective concessions' and did not. The result was that no qualified engineer was taking responsibility for their quality. Fixing the process meant getting credentialed engineers to assess and incur liability for the solutions, which is how the professional engineering licensure system is supposed to work.
>Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems.
I mean, you make my point. At no point did I say engineers are the only required component, but without the responsibility of an engineer signing off on its technical adequacy we have loads of historical proof that people end up dead far more often.
That is your belief, but I've never seen that belief backed by fact.
Most open source software disowns liability in CAPS in the license. Yet somehow FOSS like Linux gets used for safety critical infrastructure.
Microsoft would love certification requirements for engineers - that would kill open source to their conpetitive benefit.
Do you honestly think if we required Microsoft Certified Professionals to sign the internals of Microsoft OS then Windows would be more secure or reliable?
The bigger issue is that signatures and criminal consequences hardly matter across jurisdictions.
The capitalist issue is that businesses want scapegoats when things go wrong. That would be the outcome of signatures: engineers as fallboys for systemic failures across organisations.
Note how often pilots are blamed for accidents due to the design of planes.
It is just an idealistic belief based on feelies that software certification would achieve the goals you imagine it would.
Signatures are an anachronism: from an alien past.
International business uses different mechanisms for safety.
Our world is intertwined complexity. You somehow think that the buck should stop at engineers?
If engineers signed off on everything then we'd have no more disasters like New Orleans floods?
Who signed what for the Grenfell towers tragedy? Which engineers were reprimanded? Did they decide that more signatures would help prevent future disasters?
That’s because computers are Turing complete anything is technically possible and comes down to the time quality cost triangle. Most management thinks they can optimize that triangle by squeezing the living bejesus out of their teams.
I always wonder who the hell is clicking these ads. I skip all you tube ads (thanks Adblock)… I never click banner ads on principle. I assume anything paying for my eyeball time is a scam.
So who is this shit working on? These companies must have detailed profiles on “people who do what we tell them” as a whole class of people. Scary.
Honestly I wouldn't be surprised if the majority of actual end customers/humans (i.e. not bot farms or paid for actors) who click are not clicking on purpose. I've seen so many bad Android apps that have performance issues where content is still rendering and by the time you've tapped on where you go an add banner/link loaded up and registered you clicking on that. Zero purchase ever done but numerous 'ad clicks' generated
Improvement means being able to do more complicated things more reliably. Relatedly, it means being able to learn to do new things with fewer and fewer examples. We are running out of easily verifiable or simulation-friendly or data-rich domains for LLMs to conquer. (Note that I didn't say "simple" or "easy" domains.)
I suppose the next (and more risky) step is to let AI conduct its own real-world experiments, so that it can generate data to learn more physical and social properties.
It is doing that already - every day 1B people or more use AI for the tune of a few trillion tokens. Imagine that much language flowing between brains and AI agents. It carries real our world problems to AI, their solutions back to us, and we act in the world and come back for more AI iteration. In the end AI gets inside the loop of real world actions and their consequences. AI logs stretch over years, tracking downstream effects. Hindsight can be used to track consequences of prior actions. It's a real data loop, an experience engine.
This same process has recently been under scrutiny when mathematicians claimed AI companies trained on their unpublished logs and later claimed merit for results. But the exchange of experience happens across all domains. Experience gets generated at amazing rates, and absorbed by models which get applied everywhere, collecting more experience.
The trivial idea that there are some benchmarks for a tool and there can be even better inexplicit ones, and if the tool is capable of modifying itself towards better benchmarks results there could be a recursive climbing of those benchmarks through iterations of tool versions which are outputs of former tool versions.
Is this shocking? Grokipedia is an opaque system designed to confirm the opinions of its owner. Why should we expect any kind of coherent transparency?
And now the other aspect of the trade off is token budget allocation.
The author seems to be in a situation where you can burn as many token as you want. I don't know if that's a general situation.
(Even if you don't care about the environment impact of your computations, there is a dollar bill associated, and _someone_ cares very much about that.)
I can foresee a situation where devs will have to decide on how they allocate a fixed token budget - and then, faced with the option of "burning tokens to add a new feature requested by a customer for tomorrow's demo" or "burning tokens to maybe make the app faster in some edge case", the trade off will look a lot like the ones organisations made with human dev time.
This assumes that tokens are not going to get dramatically cheaper. I can't predict the future, but I don't see a path to that (or, are local models, and "a TPU in every machine" going to make the question irrelevant?).
I can definitely see a path were tokens get massively more expensive (let's meet six months after anthropic's IPO and check :D)
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
reply