Hacker Newsnew | past | comments | ask | show | jobs | submit | killbot5000's commentslogin

This is pure laziness aka “reduced time to market” on the part of Flock.

It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.

Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.

Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.

Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.


The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false.

If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.


Don’t worry, your elected representatives won’t be bothered by trivialities such as facts either way.

They can be recalled and/or replaced, as many have who voted for data centers.

They fought against datacenters. Now they are running for local offices - https://www.theguardian.com/us-news/2026/sep/15/datacenters-... - September 15th, 2026

https://news.ycombinator.com/item?id=49375000 (citations)


Only a handful of states have any concept of a recall election.

Indeed, have to wait for elections when recalls aren’t an option. Elections arrive eventually.

Exactly. It helps they also control who can even run for office in any meaningful way. Nobody fights the left harder than Democrats. Good luck finding a representative that is against data centers, flock, Israel, congressional stock bans and pausing and regulating AI, views overwhelming popular with the majority of the actual American public.

My experience is that nobody fights the democrats harder than "leftists".

Funny. In my experience, nobody fights the “leftists” harder than the Democrats. I think the Republicans fight the Democrats harder than anyone else, and aside from the “leftists”, no political group seems to really fight the Republicans.

You are misunderstanding basic political terminology then, if you think it's somehow odd that leftists are against Democrats. Democrats and Republicans are both capitalists and liberal in the classical sense, both of which leftists oppose.

>Good luck finding a representative that is against data centers, flock, Israel, congressional stock bans and pausing and regulating AI, views overwhelming popular with the majority of the actual American public.

That is rapidly becoming Democratic party orthodoxy. At the very least there are a sizable number of Democrats who fit that.


Don't know why you're getting downvoted, but hackernews is very anti-democratic in nature. One thing politicians quickly realize, especially local ones, is that you do have to be accountable to voters at the end of the day. One or two bad stories is enough to sink a local race too, or at minimum require a massive spend to overcome the negativity.

Local politics is where you understand how effective a handful of people can truly be.

Happy to read people are understanding the true power they have collectively instead of as individuals.


Oh yeah, totally agree, the HN zeitgeist is what it is.

It’s not laziness, it’s hyper focus on compliance. CJIS is the policy maintained by the FBI that handles information security, which is derived from standards built around paper.

Adding more weirdness, the details get worked out by each state.

My guess is they encrypted whatever is criminal justice information (license plate hotlists, etc) or protected by local laws (DMV data) and left the rest to make it easier to deploy and service. Remember pictures of you or your car taken in public are not protected or in scope.

Police tech is garbage and usually driven by federal grant spending. So it’s going to be interesting to see how Flock and Axon grow the business as it turns into a service model.


My problem is that Claude kept screaming across several sessions that it echo'ed a default password for a local, ephemeral development container into a session across SEVERAL sessions.

I get dinged continually for a vendor supplied container that writes an appropriately scoped access key to disk in plain text on startup (we are working to eliminate it but it requires migrating to an entirely new way of doing things the vendor only released earlier this year and I got derailed by other priorities).

So like if established enterprises using off the shelf scanning software are breathing down my back about this...what the actual hell is happening inside flock that this was fine. Lol.


The question is, why should they care at all? Will this hurt their business?

Any breach of security on a system like this is a big flashing red-alert to me.

If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.

Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.


Getting persistent access to Flock's internal network is a high-priority item for every US adversary, who doesn't want free intel collection on the movements of persons of interest? Knowing who the FBI and local cops are monitoring in is the counter-counter-intelligence cherry on top of a self-inflicted dragnet surveillance cake.

Any entity with access to flock servers can virtually stake-out anyone/everyone driving past Flock camera to monitor their movements. In a hot war, this would provide actionable data to support assassination via road-side bomb/drone strikes.


I mean... currently any cop can do that, and it's a lot easier to bribe a single cop than to break into flock network.

https://edition.cnn.com/2026/08/26/us/flock-kentucky-police-...

A single cop can do it 2000 times it seems before they get caught

And it's not a lone case: https://www.washingtonpost.com/technology/2026/08/02/how-pol...


.. with friends like these, who needs enemies

That's why you or I would care, but that doesn't answer the question of why they would.

Large companies tend to be amoral. Unless it affects them monetarily (possibly indirectly) they're not going to care. Given what they do to make money, I don't see any of these things hurting them.


It's a red-alert to you and me, but Flock won't care. People already don't want these cameras in their cities, but police departments buy them anyway. What does it matter if there's one more reason you don't want them?

Apparently police are accessing the network via their personal devices. I highly doubt their security practices online are any better than this. I wouldn't be surprised either to see things that chinese manufacturers do such as intentional back doors.

Overall this goes from disappointing to fairly repugnant.


Allegedly you can buy credentials on the darkweb to perform national searches. Might explain why some of the logged reasons for recent searches were “LMAO”

The normal explanation is plenty, unless you’ve never met, read about, or heard anyone talk about, law enforcement officers (who are human beings - for better and for worse).

How many of us have had coworkers who put something like that into a commit message? And that's a message that's at least notionally supposed to be helpful to you or your coworkers, rather than existing purely for the purposes of oversight you don't want in the first place.

I would expect law enforcement coworkers to understand the law, department procedure, and public requests for their data. That’s expecting too much from the academy, I guess.

Those that fail to meet standards should be fired to spare the taxpayers from the lawsuits coming from AI-assisted complainants.

It’s also too much for Flock’s YC-funded technology to implement a field filter that rejects “LMAO” as a valid request.

At the very least, your local staff’s nationwide stalking credentials being harvested by phishing and abused by others should carry criminal negligence penalties. Governments should pass that liability onto this YC-funded startup company.


It’s a federally protected right to skip over law enforcement officers candidates because they rank too high on an aptitude or IQ test.

Reasonable people would expect what you expect. We are not reasonable people.


This meme will not die, and here you can see it blossoming into something even weirder.

There is one (1) case in the literature, back in the early 2000s, where a department rejected a candidate as overqualified based on a cognitive assessment; the rejected applicant took that department to court and lost.

That's it; that's all the evidence.

Against that: most police departments around the country administer written tests with general cognitive components for which there is a floor score and no ceiling (the POST, the NTN, &c). And virtually no departments --- none I'm aware of --- administer IQ tests.

From all this, we've now got "a federally protected right"?


Yes, that’s how court / legal precedent works - for better and for worse.

Feel free to consult an attorney.

Edit: I thought the case went further up - but, “persuasive precedent” for other jurisdictions now exists all the same.

Edit2: since I’m seeing the username of someone with a decent clue,

> and no ceiling

was there one on paper for the hiring standards of the dept in the case in question?

Does that matter?, if there’s no legal issue with using it as a disqualifying factor? - for any candidate - whether or not they even score well?


Literally the only thing you know here is that one department didn't like one candidate and came up with a reason to deny him based on cognitive overperformance. For all you know, they didn't like his hair color, and came up with an excuse. And that's it: out of over 15,000 police departments in the US, almost 1,000,000 sworn officers, and over 25 years, this is the evidence you have for the claim that there's an enshrined "right" to reject police officer candidates who are "too intelligent".

It's an Internet urban myth. I'm just stepping in to call it out as such.


That it’s legal precedent is not Internet urban myth lol - regardless of the side-story of how the precedent came to be.

Many moons ago, I was involved in the technical side of volunteer work for domestic violence victims escaping abusive relationships with e.g. law enforcement (cops), who even fifteen years ago had sweeping powers to track and stalk their victims. Things like actual anonymous burner phones and the ability to e.g. create new email accounts without government identification were critical to the process of getting these people out safely, or alive, without fear of retaliation.

I can't even imagine how difficult this job must be nowadays, with bullshit like Flock spanning hundreds of police departments participating in their nationally-linked database. I have zero sources for what I'm about to say, but my instinct is that the political machines (expanding powers hidden behind "think of the children") behind how technology is evolving today has gotten people killed.


Quite potentially, yes. Their name is already mud among many voters, if they're shown to be treating data insecurely then that's another reason why local governments might consider terminating contracts with them.

Feels like their purpose is to test the boundaries, take the hits, and eventually sell off

They want the good, bad and ugly to flock to them as it were and vaporize them so Axon and Motorola Solutions can just pick up right where they left off. And people will just ignore or forget it because it's not the same company.

Is there any recent example of a company getting breached and its data exfiltrated, where the business was actually hurt? I predict we'll get a standard boilerplate "We take security very seriously" press release, a narrative that blames the evil hackers entirely and not the company's negligence, and then that will be that.

Would the DNC in the last US national election count?

was there really any meaningful fallout though?

I really hate how Product Managers somehow get to take the reins of engineering teams instead of having to sell them product ideas.

It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.


Because software engineering is not professional engineering.

Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult.


Do you feel like an inadiquate imposter or something? I'm assuming you work in software.

Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design.

Or read about engineering failures like flight QF32 (mostly a success story):

  A paperwork review showed that the required signatures were missing from 131 out of 138 retrospective concessions issued between 2009 and 2011
https://admiralcloudberg.medium.com/a-matter-of-millimeters-...

Australian Quantas, with a UK Rolls Royce engine on an Airbus, with engines maintained in Aussie.

Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems.

Certification matters less than you might think across international borders.

Perhaps I'm a cynic, but beliefs in certification seem so irrational to me. What is it? Jealous desires for status? Desire to have guilds/gatekeepers? Complete misunderstanding of how safety occurs in "real" engineering?


Your conclusion seems at odds with your evidence: the quote you reference indicates that a professional engineer was meant to examine the 'retrospective concessions' and did not. The result was that no qualified engineer was taking responsibility for their quality. Fixing the process meant getting credentialed engineers to assess and incur liability for the solutions, which is how the professional engineering licensure system is supposed to work.

>Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems.

I mean, you make my point. At no point did I say engineers are the only required component, but without the responsibility of an engineer signing off on its technical adequacy we have loads of historical proof that people end up dead far more often.


You believe signatures by engineers matter.

That is your belief, but I've never seen that belief backed by fact.

Most open source software disowns liability in CAPS in the license. Yet somehow FOSS like Linux gets used for safety critical infrastructure.

Microsoft would love certification requirements for engineers - that would kill open source to their conpetitive benefit.

Do you honestly think if we required Microsoft Certified Professionals to sign the internals of Microsoft OS then Windows would be more secure or reliable?

The bigger issue is that signatures and criminal consequences hardly matter across jurisdictions.

The capitalist issue is that businesses want scapegoats when things go wrong. That would be the outcome of signatures: engineers as fallboys for systemic failures across organisations.

Note how often pilots are blamed for accidents due to the design of planes.

It is just an idealistic belief based on feelies that software certification would achieve the goals you imagine it would.

Signatures are an anachronism: from an alien past.

International business uses different mechanisms for safety.

Our world is intertwined complexity. You somehow think that the buck should stop at engineers?

If engineers signed off on everything then we'd have no more disasters like New Orleans floods?

Who signed what for the Grenfell towers tragedy? Which engineers were reprimanded? Did they decide that more signatures would help prevent future disasters?


That’s because computers are Turing complete anything is technically possible and comes down to the time quality cost triangle. Most management thinks they can optimize that triangle by squeezing the living bejesus out of their teams.

I keep waiting for the post explaining that this is a joke

Well the name Pion translates to Pawn in French. So that's a good start.

Like polsia is aislop backwards?

I thought it was a joke and I laughed out loud

I always wonder who the hell is clicking these ads. I skip all you tube ads (thanks Adblock)… I never click banner ads on principle. I assume anything paying for my eyeball time is a scam.

So who is this shit working on? These companies must have detailed profiles on “people who do what we tell them” as a whole class of people. Scary.


My elderly parents regularly click the sponsored links in Google search results.

I don't think it even registers for them that they're ads (even though I have informed them multiple times).

Same for sponsored items in Amazon search results. As an adblock user it's really jarring to see their experience of the web compared to my own.


Honestly I wouldn't be surprised if the majority of actual end customers/humans (i.e. not bot farms or paid for actors) who click are not clicking on purpose. I've seen so many bad Android apps that have performance issues where content is still rendering and by the time you've tapped on where you go an add banner/link loaded up and registered you clicking on that. Zero purchase ever done but numerous 'ad clicks' generated

Can someone define “improvement” in this context? This concept feels like a buzz word otherwise.

Improvement means being able to do more complicated things more reliably. Relatedly, it means being able to learn to do new things with fewer and fewer examples. We are running out of easily verifiable or simulation-friendly or data-rich domains for LLMs to conquer. (Note that I didn't say "simple" or "easy" domains.)

I suppose the next (and more risky) step is to let AI conduct its own real-world experiments, so that it can generate data to learn more physical and social properties.

It is doing that already - every day 1B people or more use AI for the tune of a few trillion tokens. Imagine that much language flowing between brains and AI agents. It carries real our world problems to AI, their solutions back to us, and we act in the world and come back for more AI iteration. In the end AI gets inside the loop of real world actions and their consequences. AI logs stretch over years, tracking downstream effects. Hindsight can be used to track consequences of prior actions. It's a real data loop, an experience engine.

This same process has recently been under scrutiny when mathematicians claimed AI companies trained on their unpublished logs and later claimed merit for results. But the exchange of experience happens across all domains. Experience gets generated at amazing rates, and absorbed by models which get applied everywhere, collecting more experience.


That sounds terrifying.

Which means someone is already working on it.


Models that are strong enough to improve themselves without a human (I.e. ai researcher) in the loop

The trivial idea that there are some benchmarks for a tool and there can be even better inexplicit ones, and if the tool is capable of modifying itself towards better benchmarks results there could be a recursive climbing of those benchmarks through iterations of tool versions which are outputs of former tool versions.

Is this shocking? Grokipedia is an opaque system designed to confirm the opinions of its owner. Why should we expect any kind of coherent transparency?


This. It’s not even worth discussing.


As long as there’s a trade off between experimentation and performance, software will always be slightly too slow.


And now the other aspect of the trade off is token budget allocation.

The author seems to be in a situation where you can burn as many token as you want. I don't know if that's a general situation.

(Even if you don't care about the environment impact of your computations, there is a dollar bill associated, and _someone_ cares very much about that.)

I can foresee a situation where devs will have to decide on how they allocate a fixed token budget - and then, faced with the option of "burning tokens to add a new feature requested by a customer for tomorrow's demo" or "burning tokens to maybe make the app faster in some edge case", the trade off will look a lot like the ones organisations made with human dev time.

This assumes that tokens are not going to get dramatically cheaper. I can't predict the future, but I don't see a path to that (or, are local models, and "a TPU in every machine" going to make the question irrelevant?).

I can definitely see a path were tokens get massively more expensive (let's meet six months after anthropic's IPO and check :D)


Can’t tell if this is sarcastic


These are all bots and shills


Voting with your wallet can work, but consolidation increasingly makes voting with your wallet a double or triple whammy.

1) alternatives may be more expensive by dollars

2) alternatives may be more expensive by time

3) time/money lost to altered consumption has proportional opportunity cost

Market consolidation reduces the cost of using “bad” services and increases the cost of using “good” services over time.


Or a shot in the back.


Not if your spells cast their own spells.


Read the article.

They are saying very clearly the models are not casting their own spells…yet. But looking at trends and speculating when they may start doing so.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: