License plate reader searches should require a warrant
andrewpwheeler.com
andrewpwheeler.com
Seems like a nonsense comparison either way. These cameras are in public places and provide surveillance intel for governmental entities.
You could say the same about literally any privately operated device. ‘I don’t know why they call these things cell towers. They do whatever they are programmed to and can be reprogrammed by anyone with access’
Heck the same applies to non electronic things too ‘why do they call it a house? It’s a general purpose structure and could be turned into a shop or a factory or a crack den at any time by anyone with access’
Obviously the electronic networked solution is going to be cheaper and easier to operate. It would be insanely wasteful to force government organizations to use expensive cumbersome processes just to ensure they can’t be misused.
The solution is legislation and enforcement of rules that constrain what local governments are allowed to actually do with equipment they install and the data it collects, not regulation of what the equipment they install could theoretically be converted to accomplish.
for the record: whatever they're called, and in fact even if they just POSTed txt license plate numbers, i'd still be opposed because they're collecting info about people who've done nothing wrong (unlike red light cameras).
(To be clear: the government requires you to display a license plate on your car. They do not require that you broadcast an identifiable Bluetooth signature as you drive around. If you happen to do so - something you have a choice to avoid - it seems disingenuous of you to say ‘I don’t want anyone to take any notice of the Bluetooth and WiFi signatures I choose to broadcast’.)
As others have noted, I believe the brightline is less “general purpose computer…” and more “…that is remotely accessible & modifiable effectively anywhere in the world”. I worry not just about OEMs and cops, but also criminals, foreign intelligence agencies, etc. Honestly potentially anyone at this point, now that folks have figured out you can use LLMs to do analysis.
This is a sound foundation for concern by itself, don’t you think?
Neither philosophy seems to have a good limiting principle for what they mean governments should be allowed to do to efficiently enforce traffic law
It is broader than that though, and is the distinction I sought to capture with “anyone with access” in my original post. They are connected to the internet, and to a cloud no less! Anyone could be the NSA now, from anywhere in the world. I bet we’ll see these used to collect marketing data too.
Perhaps a limiting principle can be that we simply do not use ALPRs or other surveillance tech, or at least that we don’t connect them to the internet and require a warrant to access and use their data? Personally, I’d just prefer cops enforce traffic law the old fashioned way.
So we’re talking about trading off your concerns over potential abuse and misuse of technology vs concerns about potential abuse and misuse of police powers vs just allowing traffic to kill more cyclists and pedestrians.
The nihilistic libertarian says ‘precisely - government doesn’t work - we can’t hope to make things better by concentrating power’
An optimistic democratic-institutionalist says ‘we can constrain governments at the ballot box and with constitutional limitations’.
I suspect our disagreement lies somewhere in the chasm between these world views.
There's no malintent with it, it just means that the public conversation hasn't gotten to a point where these distinctions can easily be made to a wider audience. We'll get there.
Do you really think people don’t know how they’re framing the situation when they choose to use language this way? It’s all just an innocent misunderstanding, that just so happens to serve the interest of existing power structures?
I'm talking about the random schmos out there who don't know what "ALPR" even is. These folk are more and more learning about what these things are and pushing back on them.
Because its useful messaging to disarm the populace. "License plate reader" sounds less alarming than "Internet connected camera" or "Mass surveillance device."
Public attitudes vary around a "license plate reader" but will be more uniformly opposed to "Widespread, automated government mass surveillance tracking your every move via camera in real time"
Smart glasses obviously change that equation quite a bit.
But they can’t come close to the panopticon of video cameras everywhere, all the time, capturing everything for years of record-keeping.
Supreme Court recently ruled that you need a warrant for even the geofence data lookup from 3rd party recently.
That's my impression anyway.
But "anonymous sources" and similar evidence laundering has been in a thing in domestic law enforcement since SCOTUS started imposing prophylactic procedural protections in the 1960s. It was just ad hoc. But now states like Texas and California have built their own intelligence agencies which are beginning to push the boundaries of both mass and targeted surveillance similar to the NSA, and through ubiquitous digital communications and third-parties like Flock, police departments have also organically grown their own whisper networks that allows them to systematically and efficiently do what was ad hoc before.
That said, unlike the post-9/11 NSA parallel construction which was knowing and deliberate and something of an open secret at both the NSA and parts of Federal law enforcement, I think state law enforcement personnel believe they're well within the law. And interestingly I was recently speaking with an FBI financial crimes investigator about this stuff and he had never even heard of the term parallel construction. Building durable parallel construction processes requires maintaining plausible deniability, and the best way to do that is to keep most law enforcement personnel and, preferably, all district attorneys out of the loop and ignorant to what's going on. That happens by high-level officials quietly tasking a handful of mid-level people to launder the evidence. And in that sense parallel construction will never be ordinary practice the way people assume as the vast majority of law enforcement personnel will never see it happening, or at least recognize it for what it is, except for when they do it themselves in an ad hoc manner.
They were always internet connected and mass surveillance. It's the addition of search that changed things.
> No one expected doorbell cameras to join a mass surveillance network
Doorbell cameras were at least for individual security, initially. There's no attempt being made to market Flock as anything but mass surveillance. Surely we all expect them or their successors to be detecting peoples' faces, walking gates, and who-knows-what-else in the near future.
"Warrantless mass surveillance technology" creates a category into which these and similar devices can be aggregated together where people's concerns tend to be about the same.
That phrase was suggested by a local chief of police while we were having discussions on policy.
The flag for whether the object/person is law enforcement vs not is interesting as well.
Love that, very cool for quickly filtering out the streams / geodata that might have an officer's actions recorded.
https://docs.flocksafety.com/developer-hub/docs/tracking-obj...
Plenty of people did? That was obviously one of the end goals for cloud connected devices pushing recordings to a remote side for processing and storage. Especially when stuff like facial recognition was implemented server side.
I would be highly surprised if this was not pitched in the first internal product meeting.
While I give some grace to the regular population on this topic - anyone posting on HN should have trivially seen this outcome as not only likely, but nearly written in stone. Even if all your imagination captured was “secret NSA warrant” it would be one of the first risks you’d imagine for such a product.
It was obvious that this was the final outcome even back when Facebook first implemented tagging friends in photos before image recognition got cheap and good enough to go back and time and correlate the social graphs of everyone.
The Super Bowl commercial that Ring put out about finding lost dogs spooked people for a reason!
> I give some grace to the regular population on this topic
There is a huge difference between storing and processing recordings for a customer's own use, and aggregating them from multiple sources for organized mass surveillance. With that said, most corporations do not have the principles to resist the latter.
https://www.smatstraffic.com/blog/bluetooth-and-radar-traffi...
"They detect Bluetooth or Wi-Fi signals emitted by mobile devices inside passing vehicles and capture the device’s MAC address, a unique identifier that allows the same device to be recognized at multiple locations"
No one? There's a reason I never bought one of these things. This was a pretty obvious outcome to anyone who even slightly distrusts corporations or the government.
This middle ground that municipalities try to carve out where it’s fully open to police without a warrant but not subject to FOIL laws doesn’t appear tenable for much longer.
There’s been too many cases of police officers stalking exes, poking around the data for fun and such so it’s clear police cannot be trusted with the data without better court oversight.
It’s certainly a very powerful investigative tool, but needs solid 4th amendment protections. The Supreme Court’s recent ruling on geofence searches of cell phone records is a good indication on where the Supreme Court’s head is at on this sort of thing, where they said no you can’t just do blanket data dumps like that without a warrant.
Going back through police officers' notes or cruiser dash cam videos and tracking a car's movements by its plate is not an illegal search, is it? Just cumbersome, expensive and likely ineffective. Well, now it's not. A difference in degree (of usefulness and speed), not in kind.
But often the inverse argument is used in respect of private corporations. Obviously it would be unreasonable to expect Google to vet every ad and YouTube video uploaded tot heir platform, and make responsible editorial decisions about which ads and content to show to children. Surely to allow them to scale arbitrarily large we must make sure not to overly burden them with regulations.
I am actually not so sure that’s obvious. I am slowly coming around to the controversial opinion that if they can’t vet what is going up, they shouldn’t be allowed to have an infinite number of uploads/hosted content.
They constantly alternate between “don’t worry, we have perfected our algorithms and can catch all of the stuff” and, when they fail, “well you can’t expect us to go over all this stuff. But don’t worry, we pinky promise it’ll be different now.”
If I owned 10,000 apartment buildings and one of them collapsed because of negligence, I don’t simply get to go “my real estate empire is too big for you to expect me to follow the law. Shit is just going to collapse sometimes, deal with it.”
Efficiency would be great if it was used to save money. But surely you've heard of the Jevons paradox. This kind of cheap surveillance does not make the government smaller and it has all kinds of bad effects.
> even though the population and economy and complexity of the world the government is tasked with regulating scales up.
Car stuff isn't changing much. They don't need better tracking of where you drive.
> But often the inverse argument is used in respect of private corporations. Obviously it would be unreasonable to expect Google to vet every ad and YouTube video uploaded tot heir platform, and make responsible editorial decisions about which ads and content to show to children. Surely to allow them to scale arbitrarily large we must make sure not to overly burden them with regulations.
Well, vetting every video would not be reasonable even at a small scale business with the same business model.
While vetting every ad is very possible.
I don't think I've seen anyone claim youtube is unable to vet ads if they significantly wanted to?
> vetting every video would not be reasonable even at a small scale business with the same business model.
A small scale business like… a cable tv company? They certainly historically were assumed to be responsible for every piece of video content they took from a creator and broadcast.
That is a true statement that is very different from my claim that they could.
> A small scale business like… a cable tv company?
No, cable is a very different business model. If youtube only allowed business accounts worth millions of dollars it would get halfway there. And it would be the end of "you"tube.
As a private citizen, I can't just legally look up a license plate and get an owner and address due to data privacy laws.
I suspect when there’s been a few cases of that sort of thing happening the attitude of local politicians towards these cameras will change quite quickly.
I generally thing this data is a good thing, provided it’s locked behind solid 4th amendment protections.
Yes, and I keep thinking an organized, crowd-sourced effort like people do for capturing ADSB data or weather stations would be tempting. Setting up the hardware would be a little more involved though (mostly because of needing to locate it near the street). Cost is probably not even much worse than an ADSB monitor now.
Something like this is probably inevitable, either as a grassroots effort or via something like Amazon's Ring network. Short term it could prompt officials into action, but I fear long term it would be bad for society - laws might be written to prohibit it, but those would have side effects of limiting other things (like the aforementioned ADSB monitoring network).
e.g.:
Arkansas: https://law.justia.com/codes/arkansas/title-12/subtitle-2/ch... > Except as provided in subsection (b) of this section, it is unlawful for an individual, partnership, corporation, association, or the State of Arkansas, its agencies, and political subdivisions to use an automatic license plate reader system.
Maine: https://legislature.maine.gov/statutes/29-A/title29-Asec2117... > Except as otherwise provided in subsection 3, a person may not use an automated license plate recognition system.
Likewise I would expect that the license plates read be redacted. It makes sense to protect it since you are exposing members of the public, not the government.
Once you redact license plate numbers, what is left of substance in the FOIA request?
But a pretty huge difference. It's the difference between a few individuals throwing waste into a river vs a corporation systemically polluting it. Surely one is more of a problem than the other?
EDIT: i have no doubt that Flock and other ALPRs got so widespread because four ALPRs watching each direction at an intersection is basically invisible in comparison to four cop cars at every intersection.
if plate readers were as visible as cop cars (including agency branding) people would have probably gotten bent out of shape a long time ago.
"We believe your camera captured the guy who robbed your neighbor, can we see the footage". Virtually everyone says yes to this.
There's no evidence that mass video surveillance, Ring cameras, etc. are leading to higher clearance rates of serious crimes.
> We have had cities in the USA with 10k+ cameras in public spaces for years now without much fanfare.
And if the data from those cameras were processed to allow me to type someone's name into the search and then track their every movement, there would be a lot of fanfare. Palantir is probably building that, but it doesn't seem widespread yet.
But as of now, the directionality is reversed.
With regular video, we know a crime happened and expand our search from there to find a suspect. It's not invading a specific person's privacy.
With Flock, we have a suspect and want to retroactively stalk that person. We don't know if that person had anything to do with any crime yet, and we're invading their privacy.
There is nothing reversed with Flock. There is a crime scene, they see who was entering or leaving and work from there. Without plate readers it takes a team of people many hours, that’s the difference. You can’t know who had anything to do with the crime without investigating, that’s the definition of the word!
> … we're invading their privacy
Who expects privacy driving on public roads? In any sort of developed area you are driving past cameras on every single street. Every Uber has a dash cam, the Teslas are recording (sometimes?), every police car has a camera, etc.
Interesting how you reframe that, because the police would absolutely need a warrant to put a GPS tracker in your car.
This kinda proves everyone's point about this sort of thing, an officer following you is clearly different from the omnipresent surveillance dragnet enabled by Flock cameras.
Well that's not the tradeoff. It's impossible for everyone against cameras to get their own police shadow everywhere. When it takes that much labor they are forced to keep the average amount of surveillance down to reasonable levels.
We could also talk about restricting that kind of surveillance without a warrant, and stuff, but it's such a smaller problem. I wish my biggest surveillance risk was police pouring money down the drain to follow me around.
This is a huge problem that people will try to sweep under the rug or hand wave away with wording like "It's the scale the matters".
Ideally, laws need to be written like programs are, where fundamental rules of the system are derived and programmatically put into action. So words like "scale" mean nothing. "I need the variable to go negative when the scale is large". Most programmers here will immediately snag on "scale" not being a hard value.
So what we actually need is a redefining of the fundamental rules, and well, that is very challenging to do such that it's still legal to walk around an record everything in public, but not legal to passively record everything in public all the time. How do we solidly and unambiguously differentiate a cops dashcam, from a police camera on a portable base station, from a flock camera on a corner to a private business with a security came to a firestation with a security camera.
Legally it's a very challenging problem to create a "programmatic differentiation" from the kind of camera use we want, and the kind we don't want.
What is the difference between a security camera watching the municipal tools shack entrance and the security camera watching the main road?
The ultimate goal is to not have a massive database of everything that happened everywhere going back forever. So it even extends far beyond just reading license plates.
> Legally it's a very challenging problem to create a "programmatic differentiation" from the kind of camera use we want, and the kind we don't want.
I don't think that's ideal at all. The questions you're asking already have been answered, judges. It's their whole job to understand that scale changes things.
I get the instinct to be able to objectively codify things, especially in this community, but the law is based on morality and philosophy. Until someone comes up with a perfect solution to the trolley problem, we need a human in the loop making judgements.
More on topic, there's a reason why we have different terms for surveillance and mass surveillance. They feel very different and mass surveillance enables much different behaviors of bad actors.
It seems many people feel it limits what I would consider "freedom of impermanence", or the concept that as an ordinary individual nearly every action or mistake you make will not considered in your future.
I for one would act differently if that were the case. Many vulnerable or stupid moments would not have happened. Many of those moments have allowed me to grow as a person. And this is as a person who has not faced persecution or bias in law enforcement.
I do not have a stance on the matter of general recording currently, but know that I would have acted differently if there was a camera around all the time. There goes my first time asking someone out, there goes frying a 5V board with 12V because I thought I knew better, there goes bar karaoke so bad that even the bartender looked pained. But if this were law, so too goes the guy I saw in a park fire spinning, so too goes the joy I captured on a strangers face at seeing a beautiful chandelier, and so too goes the countless photos of nature that happen to have people in the background.
> But if this were law, so too goes the guy I saw in a park fire spinning,
He would have been there without you seemingly. Everyone who saw him there would have seen him. You meant your recording?
> so too goes the joy I captured on a strangers face at seeing a beautiful chandelier,
They would have seen the chandelier and felt joy without you seemingly. You meant your recording?
Did you ask to send them a copy? Did you ask to keep it? Did you ask to share it?
> and so too goes the countless photos of nature that happen to have people in the background.
A recording of a person and a recording of nature which happens to have people in the background are different. And some countries understood this when they made their laws.
And no, I did not discuss this with the people in the images. I only share these things in person so I am not too concerned with it spreading. On occasion I will offer a copy for the person (often the time I realize I have a good photo is weeks after the fact).
Do you have countries in mind? Photography laws fascinate me, so I’d love to read more. I only really know about the US.
For the examples I gave, I used a situation with implied consent but not explicit (a person performing in public), a situation with neither implied nor explicit (a layperson in public), and a situation that may not need consent (a non human subject with people visible). It would be interesting to know if each of those would be handled differently.
Scale actually matters. Things that are generally OK at a small scale become problematic at larger scales. A single police cruiser writing down license plates isn't able to track you in the same way a huge surveillance network is, and the opportunities for abuse are much lower.
Five cameras is less than what the number of police on duty are using.
It's obviously different in that Chatrie was about google location data, and there actually was a warrant. SCOTUS ruled that warrant was too broad since it captured everyone in that location, not a specific person(s).
Constitutional scholars have pointed out the ALPR are next in line to face challenges based on the same principles as Chatrie - LEO can get a warrant for a specific person(s) to search but cannot search the entire universe.
That would not prevent ALPRs from existing, but it would require a warrant to search them. Which seems reasonable and completely in line with the 4th amendment.
Edit: words/spelling
Compelling parties to give up data is different than looking at your own data. And it is firmly established that recording and reviewing footage in public space is totally fine.
So we are back to square one...How do we define scale such that a police camera on a police car is OK, but a police camera on every corner is not. Or that individuals can record in public but police cannot.
They wrestle with the balance there of 4th amendment protections and mass surveillance. It's evolving and generally courts are moving to not allowing mass surveillance -or less so than they have allowed in. Courts have been split on it, and someone already pointed it out that SCOTUS will eventually come up with tests for it.
There were some really interesting parts of those Chatrie opinions that really will test the idea that someone in public gives up their right to any privacy - the fundamental underpinning of why governments can currently point cameras at public places and dont need a warrant to search that video.
Chatrie protected the aggregated viewpoint versus any single public moment - And SCOTUS said the aggregated viewpoint (mass search of location data with no specific person(s)) is not allowed under the 4th amendment. A very interesting precedent.
Gorsuch had an interesting take in that he argued that in Chatrie the location data was Chatrie's personal property and therefore protected from illegal searches from government.
There are a lot of similarities to how ALPRs work, and key differences. Mostly Chatrie deals with a private firms data collection of locations - google vs ALPRs are generally on publicly owned property and recoding things in public.
Still, many justices opened the door to the idea that the government can't mass surveil citizens. We'll have to wait and see how it all plays out.
I am very much of the opinion the government should need a warrant to search through ALPR data (and video for that matter). So, I am hopeful that the tenets of Chatrie extend to ALPRs, video, etc.
Edit: Gorsuch argues that the data is personal and not the government's data - this is what prevents the government from searching for it without a warrant. He did not get into why a body cam or something like that is different.
It took 8mo for Chicago Police to review and redact bodycamera footage from a protest in Chicago. It was 95% blurred. Almost hilariously, one of the only parts that wasn't blurred was a moment where one cop commented on another cop's mustache.
So from the FOIA perspective, the public isn't able to get gobs and gobs of footage just because it's public.
Luckily we never need to do that with words for them to be useful, even in legal contexts.
All I'm saying is it should have been a problem at that point.. not just because it's easy now to do it at a high scale.
The former is massively damaging to our rights, the latter is almost useless and thus barely a problem worth talking about.
The difference in scale matters.
It's about how costly (in time, energy, money) is it to build how complete of a picture based on what level of prior suspicion?
https://en.wikipedia.org/wiki/United_States_v.Jones(2012)
> Also left unanswered was the broader question surrounding the privacy implications of a warrantless use of GPS data without a physical intrusion – as might occur, for example, with the electronic collection of GPS data from wireless service providers or factory-installed vehicle tracking and navigation services.[27] The Court left these matters to be decided in some future case, saying, "It may be that achieving the same result through electronic means, without an accompanying trespass, is an unconstitutional invasion of privacy, but the present case does not require us to answer that question."
https://en.wikipedia.org/wiki/Carpenter_v._United_States
> Ultimately, in Carpenter the court determined that the third-party doctrine could not be extended to historical cell site location information (CSLI). Instead, the Court compared "detailed, encyclopedic, and effortlessly compiled" CSLI records to the GPS information at issue in United States v. Jones, recognizing that both forms of data accord the government the ability to track individuals' past movements.[24] Furthermore, the Court noted that CSLI could pose even greater privacy risks than GPS data, as the prevalence of cellphones could accord the government "near perfect surveillance" of an individual's movements. Accordingly, the Court ruled that, under the Fourth Amendment, the government must obtain a search warrant in order to access historical CSLI records.[1]
Of course there are no guarantees on how they'd rule today, but in the past they've ruled that scale and ease of access and compilation are significant enough to mean that fourth amendment protections should apply.
To me, that is precedent in US law that computerized methods of executing human tasks do not fall under the same rules.
This is not true of privacy advocates, they do want to limit the ability to fish for circumstantial evidence that targets innocent people and causes suspicion.
Pretty big part of the conversation.
Step two look at drivers license photos for the person that most closely matches the description.
Step three take the person that most looked like the described person and ask a witness with a poor memory if that was the person.
Step four convict.
Is this actually born out in Court Cases? Warrantless Surveillance by NSA seems to be blanket legal for example.
See: https://www.oyez.org/cases/2017/16-402
It comes up fairly often here since the HN audience tends to be mostly programmers/computer people, but it's really important to remember that the law is not a series of rules a computer can directly evaluate to determine whether something is or is not legal; judges frequently use their judgement to balance the assumed intent of laws and the competing interests of various parties. I don't say this to you specifically but really just the HN audience as a whole :)
from your point, nothing is cheaper and more efficient then mandating an app on all phones through which the governments can track everyone, and consequently whoever doesnt have it would be a criminal. it completely tracks from your argument. You may need to make the app stop tracking while theyre in the home, but thats a technicality. voila. no longer an issue according to your point
Are you suggesting that people couldn’t do that for some reason?
It isn't possible for them to do that without sensors and AI everywhere. That's why using this technology is a red line.
Sheltering humans running away from slavery was also a crime .
It was illegal for black Americans to learn to read and write. Seeking education made them a criminal.
Buying or selling a beer made you a criminal during prohibition.
Do you see how easy it is to make someone a criminal?
Thankfully, the law isn't as overly simplistic and black and white as that. It'd be very stupid if it were. We have the ability maintain a general principal like "there's no expectation to privacy in public" and still prohibit certain things that are deemed harmful, like taking upskirt photos of people while they are in public spaces.
Hello, I'm here.
Practically, we do have privacy in public pre-AI. We weren't entitled to complete anonymity, but the ability to track every single person at all times was impossible.
Now that AI and sensors are making it possible, people are saying "No, I don't want that to be the norm".
You can also read Carpenter v United States for some background thoughts on why it's not as simple as Justice Fluidcruft condescendingly imagines it to be.
In fact if you're really curious, you could even look at the state cases that are bubbling their way up like Commonwealth v McCarthy.
If only everyone were as confident and simplistic as you, we could avoid all these darn cases :(
Confidence and ignorance live another day!
People do not expect their phones to be feeding their locations to cops and they do not expect things hidden on them unknowingly to exist. But it really stretches believability that people have no idea that cops check license plate. Or that cops communicate with each other about license plates to coordinate searches or that cops have databases of license plates. Heck there's a whole trope in media that you need to swap license plates to hide from cops.
Next you're going to be telling us we need a warrant for an Amber alert.
I didn't ask you to reply to any of my comments.
Also, you’re being kind of a dick. Knock it off.
That nuance is why it's worth reading the entire opinion.
Anyway here you go:
> GPS monitoring generates a precise, comprehensive record of a person’s public movements that reflects a wealth of detail about her familial, political, professional, religious, and sexual associations. See, e.g., People v. Weaver, 12 N.Y.3d 433, 441–442, 909 N.E.2d 1195, 1199 (2009) (“Disclosed in [GPS] data . . . will be trips the indisputably private nature of which takes little imagination to conjure: trips to the psychiatrist, the plastic surgeon, the abortion clinic, the AIDS treatment center, the strip club, the criminal defense attorney, the by-the-hour motel, the union meeting, the mosque, synagogue or church, the gay bar and on and on”). The Government can store such records and efficiently mine them for information years into the future. Pineda-Moreno, 617 F. 3d, at 1124 (opinion of Kozinski, C. J.). And because GPS monitoring is cheap in comparison to conventional surveillance techniques and, by design, proceeds surreptitiously, it evades the ordinary checks that constrain abusive law enforcement practices: “limited police resources and community hostility.” Illinois v. Lidster, 540 U.S. 419, 426 (2004).
> Awareness that the Government may be watching chills associational and expressive freedoms. And the Government’s unrestrained power to assemble data that reveal private aspects of identity is susceptible to abuse. The net result is that GPS monitoring—by making available at a relatively low cost such a substantial quantum of intimate information about any person whom the Government, in its unfettered discretion, chooses to track—may “alter the relationship between citizen and government in a way that is inimical to democratic society.” United States v. Cuevas-Perez, 640 F.3d 272, 285 (CA7 2011) (Flaum, J., concurring).
> I would take these attributes of GPS monitoring into account when considering the existence of a reasonable societal expectation of privacy in the sum of one’s public movements. I would ask whether people reasonably expect that their movements will be recorded and aggregated in a manner that enables the Government to ascertain, more or less at will, their political and religious beliefs, sexual habits, and so on. I do not regard as dispositive the fact that the Government might obtain the fruits of GPS monitoring through lawful conventional surveillance techniques. See Kyllo, 533 U. S., at 35, n. 2; ante, at 11 (leaving open the possibility that duplicating traditional surveillance “through electronic means, without an accompanying trespass, is an unconstitutional invasion of privacy”). I would also consider the appropriateness of entrusting to the Executive, in the absence of any oversight from a coordinate branch, a tool so amenable to misuse, especially in light of the Fourth Amendment’s goal to curb arbitrary exercises of police power to and prevent “a too permeating police surveillance,” United States v. Di Re, 332 U.S. 581, 595 (1948).[1]*
=======
Now the question is: is this characterization true only of GPS monitoring? Or is it also true of a sufficiently broad network for ALPRs? The answer of course is the latter.
Here, Sotomayor + 4 other Justices are saying it's actually not as simple as Fluidcruft's "you're in public so plain view doctrine answers it"
The actual opinion in U.S. v. Jones hinges on the fact that "The Government physically occupied private property for the purpose of obtaining information," and also stated "[t]his Court has to date not deviated from the understanding that mere visual observation does not constitute a search."
So the controlling opinion said: "we won't answer this question." The concurring opinion (signed by 5) said "fluidstack is wrong."
There can't be a "concurring opinion" signed by five Justices. An opinion signed by five Justices is a majority, and would constitute the Opinion of the Court.
I think that the most we can say right now is that although the "plain view" doctrine has been weakened somewhat over the last couple decades, it's not completely dead yet.
The fact is that there hasn't been a case on point to answer the questions as to whether 1/ALPRs constitute a "search" under the Fourth Amendment (a threshold question that must be answered "yes" to proceed further), 2/whether use of the technology can be "reasonable" under any circumstances, and 3/whether there are any exceptions to the warrant requirement. We have a long way to go before we know what the law is on this technology. Remember, too, that the Fourth Amendment has only a "reasonableness" and a warrant requirement. It does not ban technologies for surveillance outright. (See, e.g., Kyllo v. U.S., where the use of thermal surveillance technology wasn't the issue in and of itself, but rather constituted a search necessitating a warrant.)
So how about you tone down the attitude a bit? You're arguing from shaky ground, and there are more constructive ways to contribute to this debate.
What I meant is that both the concurring opinions (signed by 5 collectively) agreed on this same point:
> society’s expectation has been that law enforcement agents and others would not—and indeed, in the main, simply could not—secretly monitor and catalogue every single movement of an individual’s car for a very long period. In this case, for four weeks, law enforcement agents tracked every movement that respondent made in the vehicle he was driving. We need not identify with precision the point at which the tracking of this vehicle became a search, for the line was surely crossed before the 4-week mark.
So no, I'm not arguing from shaky ground. And no, ample attitude is warranted against people not just advocating for unbounded state surveillance, but insisting that it is already a foregone conclusion.
I agree with you that the two concurrences are aligned about this. Interestingly, it did not make it into the majority opinion, even though there was a majority on this point. It probably wasn't included because it wasn't needed in order to reverse the lower court's decision; the physical violation was enough to merit a unanimous decision.
> ample attitude is warranted against people not just advocating for unbounded state surveillance, but insisting that it is already a foregone conclusion.
No, it isn't. It is possible, and better, to disagree with someone while remaining courteous--even on subjects you have strong feelings about.
From our Guidelines:
> Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.
A wannabe dictator, inversely, would not say nor be happy with what I am saying: You have a right to exist as a private individual, even if going out in public would leak vast amounts of information to a drone hovering overhead.
I did say earlier, though:
> although the "plain view" doctrine has been weakened somewhat over the last couple decades, it's not completely dead yet.
The aerial surveillance cases are applicable examples of that point.
> society’s expectation has been that law enforcement agents and others would not—and indeed, in the main, simply could not—secretly monitor and catalogue every single movement of an individual’s car for a very long period. In this case, for four weeks, law enforcement agents tracked every movement that respondent made in the vehicle he was driving. We need not identify with precision the point at which the tracking of this vehicle became a search, for the line was surely crossed before the 4-week mark.
Altitude has nothing to do with it. Completeness and cost of picture does.
Also, the court has still not subjected the specific question against the Katz test. If they did, they’d might agree that a person has a reasonable expectation of privacy in their public travels. On the other hand, they might not.
I think you should consult a local attorney, because you’re not really understanding what the legal impact of these cases is, and I think a deep discussion with an subject matter expert in person would improve your understanding a lot.
https://news.ycombinator.com/item?id=49275137
Who knew?
Ah, yes, I did.
> Ah, yes, I did.
Still a dick.
Perhaps your aversion to perceived dickishness made you misread the situation.
The drone hovers directly over the sidewalk in front of your house. When you step onto the sidewalk, it follows you directly to the front of your workplace. As you go up to the third floor, it hovers up and observes you through the window. As you descend and come back out to the street, it hovers overhead until you arrive back to your home.
It's all plain view doctrine. Not sure what could be ambiguous about this.
There are cases where it's legitimately ambiguous as to where the law lands and this is one of those areas, but fluidcruft is insisting that it's not. To the extent it's not ambiguous, recent case law, the overarching history of the 4th Amendment literally since its ratification, and common sense all point in the same direction: the government cannot arbitrarily monitor everyone's movements (even in public) at near-zero cost with zero warrant.
2. There's nothing dickish in my prior comment whatsoever.
What’s wrong with this? It’s correct that there’s been no case yet on the legality of warrantless end-to-end surveillance technology, and he’s right that the Constitution has no explicit privacy right. Certainly no lawyer I know would advise their client otherwise, and as an attorney myself, I wouldn’t do it, either.
> There's nothing dickish in my prior comment
When someone tells you you’re being dickish, pay attention and take it seriously. They are giving you valuable feedback about how you are coming across. Even if you don’t intend to be that way, and don’t think you are, others can still see it. You need to take that into consideration.
In this case, saying that a wannabe dictator would use the same argument was pretty dickish, particularly in the context of everything you’ve already said to them. It’s well past the time to lower the temperature of this discussion. Don’t keep it on simmer.
If it were more dangerous to insist that these privacy rights already exist (which they do, at least since Katz), then a wannabe dictator would obviously just insist that these privacy rights exist. But... they obviously wouldn't do that. They'd in fact insist that these rights don't exist, they never have, and they're not in the text of the Constitution.
Referencing the desires of a wannabe dictator is not dickish in the context of a conversation about state surveillance powers. Perhaps you're getting too heated and reading tone into other people's words at this point?
> Referencing the desires of a wannabe dictator is not dickish in the context of a conversation about state surveillance powers.
I disagree. Again, it matters less what you think and more what impression you leave, especially in the greater context of everything else you’ve said in this discussion.
By analogy, it is absolutely true that a person has a right to self-defense. People in common dialogue should insist on this being actually true. Does that mean your lawyer should go into a courtroom with the strategy of simply insisting that's the case? No, obviously.
The invocation of Dobbs is clearly referencing a political strategy and not a trial strategy.
I am responding (quite clearly) to the proposed political strategy, while you are reading it as a trial strategy.
https://news.ycombinator.com/item?id=49294009
> they are not wrong [per my interpretation]
> you are therefore a dick
I think between 1 lawyer and 2 laypeople talking about law, it's quite likely the lawyer has the idiosyncratic interpretation. I did not fail to ask a question nor did I insult anyone. You did both.
Do you think the level of effort to correlate that data between people is the same with a bunch of people with excel as it is with an AI agent?
The only people who want that are the ones that want to subjugate large portions of the population, or those that want those large portions subjugated even if they don't get to do it.
I don't believe so. The whole purpose of a license plate is to deanonymize vehicles and their drivers. Vehicles must display license plates while driving or parked on public roadways.
This is not the same as faces. Faces are not like license plates. People are not given faces by a state licensing authority and then required to display them.
The scale of facial surveillance is a problem only because the surveillance of a single face is already a problem.
People who don't like license plate tracking should take a bicycle or public transit.
When you are given the privilege of riding a two ton murder weapon on a public road, you trade privacy for that.
Not only this, this a precedented court opinion.
> Still more fundamentally, we have never understood Fourth Amendment protections as kicking in only once an intrusion “goes too far.” Pennsylvania Coal Co. v. Mahon, 260 U. S. 393, 415 (1922) (adopting that approach for regulatory takings). Where the Fourth Amendment applies, it applies—regardless of “the quality or quantity of information” the government obtains. Kyllo, 533 U. S., at 37.
https://www.supremecourt.gov/opinions/25pdf/25-112_0am4.pdfScale does matter in what characterises a clear 4A violation.
Nationwide pervasive cross-referenced AI-augmented ALPR is a 4A violation on account of that scale.
(I'd argue that that relevant scale threshold is far lower, but probably above the single-officer-in-a-single-cruiser manually taking notes level.)
Is the line automation? Or 24/7 operation? (genuinely)
If an officer was standing next to every Flock camera in America, the public would be hyper aware of the situation we are now in.
Mass, warrantless, and perpetual surveillance is incompatible with liberty and unacceptable to the vast majority of Americans.
It has to be stopped, or we are doomed.
In that vein, I wouldn't be 100% against Flock cameras if their purpose was limited.
The problem in the concept is that they store all license plate hits for later retrieval regardless of if anything is actively tying that license plate to some form of illegal activity. Even with a short retention window, this is mass surveillance because it allows later viewing of hits based on any kind of search given. And you can never limit that search query in a 100% effective manner, but you could very well tell police departments "tough luck, we only have hits if the plate was involved in something at the time of scan".
Similar issue: cell phone interception via Stinger cell base stations by law enforcement. A U.S. judge in Ohio ruled that using the device to sweep up data from thousands of unsuspecting individuals to track one suspect gave the government unconstitutional, "unbridled discretion" to monitor private citizens.
Another similar issue: A judge in Mississippi ruled "tower-dump warrants", where law enforcement requests info from cell companies on users/phone numbers in a geographic area in a certain time frame are illegal and too broad. The judge declared them an arbitrary government intrusion that violates the Fourth Amendment's particularity requirement
A third similar issue: In U.S. v. Chatrie, the U.S. Supreme Court ruled 6-3 that reverse-location "geofence warrants" constitute a Fourth Amendment search. The ruling establishes that users maintain a reasonable expectation of privacy over their location data, meaning law enforcement can no longer execute warrantless, sweeping digital dragnets through third-party data.
These are 3 examples of large scale police surveillance that have been ruled illegal because they are broad surveillance and give police too much power without a specific legal justification. This seems very similar and I expect the court cases on ALPR cameras to end up in the same place, but it may take a decade or so.
Non-investigating would be tasks like:
- counting the number of vehicles going by - radar’ing every car to produce a report on how many people are speeding and how much - checking all licence plates for valid registrations to produce a report on what percentage of cars have expired tags on the road.
The level of observability and risk involved in using the entire nation’s police resources is extremely high, whoever asks for that much resources will have to account for what they are doing and many of the details of the event are likely to be scrutinized by many parties, media, other departments, etc. It is unlikely to be wielded to abuse or strip civil liberties or to harass people, as we’ve seen ALPR’s be used
Is it common for normal people to set up and use ALPRs?
The bigger problem is law enforcement's use of private business as end-around to dodge 4th amendment.
Google and Apple, Verizon and AT&T, auto manufacturers, Flock, and every other business that scoops up our data has a trove of information that would be unquestionably illegal for law enforcement to collect directly due to 4th amendment protections against government mass surveillance. So, instead, the businesses conduct the mass surveillance and then law enforcement gets to access that information -- either with a warrant as is the case for Google and Apple, or with some sort agreement as with Flock.
Businesses (or individuals) that deliver surveillance data to the government, compelled by warrant or otherwise, should be subject to the same constitutional restrictions as the government itself.
Also, if it's the police, at least they're part of the community and people can monitor and have an effect on what they do. When it's a private company, none of that is true.
No.
A police officer is an expensive asset that requires a lot of investment of both time and money to create. [0] When a police department chooses to put cops on a corner doing surveillance, they're choosing to prefer that activity to any other thing that that cop could be doing. In all but the smallest towns out there, it's certain that the PD doesn't have enough officers on staff to surveil every single street corner in town. In most towns, it's prohibitively expensive (in terms of training cost, opportunity cost, and salaries) to set up a dragnet surveillance when one only uses humans to do the surveillance.
In contrast, cameras are far cheaper to acquire, deploy, and maintain than cops. You also only need a handful of cops to run such a surveillance system, rather than one on every corner. With cameras owned by the police or town, it's totally feasible to set up a dragnet surveillance system in most towns.
As many folks have said in the discussion about this, scale and expense are very important considerations. As few people have said, laws, regulations, and punishments that make sense when you will catch one rulebreaker in a hundred thousand often do not make sense when you will catch one rulebreaker in two. And the sorts of regulations that provide adequate restraint to police and prosecutors from interfering in people peaceably going about their lives are not the same in a society where one has to send out police to ask people face-to-face for information about someone's whereabouts as they are when police can sit at their desk in HQ and pull up complete records of 90% of that person's daily activity with five minutes of keyboard work. [1]
[0] I make no comment as to the average quality of the asset produced. I only note that it's a very limited asset that's expensive to produce.
[1] Note that I'm not saying that the surveillance systems currently deployed provide access to 90% of everyone's daily activities. This is an illustrative example. However, it takes only a few minutes' thought to notice that the police's powers of surveillance are far greater today than they were in the late 1700s.
Crime would drop to near zero, people would be happy
If there were literally hundreds of thousands of government agents on every corner writing down every person/car that walked by, it is quite probable this would be illegal even though you have no expectation of privacy in public. See Carpenter V United States and some of the concurring opinions in United States v. Jones.
For example, an officer sitting on a city street is very unlikely to learn where his wife goes every day, an ALPR search will answer that question.
An officer walking along the street making note of what he sees is very unlikely to observe and make note of the precise daily movements of someone in August three years ago, an ALPR search will answer that question.
The degree/kind distinction you’re aiming at is meaningless, it’s like trying to argue that shooting someone with a firearm is the same as shooting someone with a paintball gun in principle, sure but maybe one of them is orders of magnitudes morw powerful and impactful, and so deserves a different degree of consideration in how and when it is applied?
The difference in scale is so great that it becomes the meaningful, defining factor.
A police cruiser sitting at an intersection is visible. People notice it and its presence changes their behavior. They may choose to avoid certain routes through a city where surveillance cruisers hang out. Flock, and similar surveillance systems, are far less noticeable. Many, many people had no idea they existed a year ago when there were already 80,000 devices installed. Flock has been hot in the news cycle lately in part because tons of people are still just beginning to learn they exist. Whereas a police cruiser on a corner is overt surveillance, Flock is a "creepier" incarnation.
There's also capability. In principle, an officer parked on a corner is capable of responding to a variety emergencies. Some people might feel that the presence of the officer there was a net good for public safety. Heart attack in the neighborhood? Your local surveillance officer can start CPR. Older person with late-stage dementia has just walked away from home? Your local surveillance officer could clear that neighborhood.
But these surveillance systems have only one capability: surveillance. They can't render aid. They can't even prevent a crime; they can, at best, discourage it, or maybe aid in the apprehension of someone who committed a crime -- and didn't take adequate measures to avoid detection.
It's not the first time.
We also see the cops use the flock system as another excuse to treat an encounter over an unpaid bill as if they were taking down Bin Laden - they seem to see "flock hit" as code for "lets try to kill this person".
I am not a criminal nor do I have some sort of fetish for being abused, therefore I don't want some typo to result in unstable, bloodthirsty thugs putting guns in my face. The inefficiency protects me somewhat from these things, and until these issues can be properly addressed, I don't want anything to be scaled to a higher degree.
Yes I'm aware that this means lazy cops won't catch as many speeders and people who have warrants to pay a fine. I don't mind.
There is already plenty of precedent in existing laws that 'automated' is a distinction that matters. Even on this exact issue, a few states prevent you as a private citizen from operating an automated license plate recognition system. You are free to scribble down the plate numbers all you want, but using an automated system is against the law.
The Fourth Amendment bans only unreasonable searches, and the threshold question is whether someone had an expectation of privacy that society is prepared to recognize as reasonable. That standard is contextual by design (what is reasonable to expect is partly technological, but partly societal and cultural). The "difference in degree" you mention is precisely what is being tested.
The recent (and oft-discussed) Chatrie v. United States is relevant. The Court held that the government's acquisition of a person's phone location history is a search requiring a warrant, and refused to set a duration floor. Their stated rationale was both that even short windows expose sensitive movements, and because they did not believe they could answer how many small violations of privacy add up to a big one. As such, the majority decided that warrants were necessary, lest the government be given a "virtual panopticon"
If we took your hypothetical seriously, an army of officers logging every plate by hand probably isn't a search and there's no reasonable expectation of privacy of movement on a public road. But building a searchable index of those notebooks, and querying it to reconstruct an arbitrary car's six months, is a different act from the observing.
That's the act at issue. Nobody argues a camera needs a warrant to see a plate.
The thing I don't understand: why do so many people want the police to _not_ need warrants to surveil the public? Are you historically illiterate? Are you unaware of how big government power tends to be abused? Do you simply trust that the government will always run by people who will support you and will abuse only the people you personally dislike?
I'm legitimately curious what sort of intellectual position you use to justify your active support of authoritarian measures, and why you don't believe the public should have safeguards against government abuse. My questions might have sounded flippant, but they were sincere. I would like to understand if your position is borne of naïveté, or a sincere preference for fascism.
System 1 can refer to the dashcam or the mk1 eyeball + notepad in your example.
System 2: a system for tracking the presence of a person across both time and location
An example of system 2 would be the facial id system being trialled on the london underground currently.
These are a difference in kind not in degree. It doesn't matter how many system 1's you deploy, you cannot unlock the capability of querying where any given face was observed across time and location.
More to the point, there’s a difference between someone writing down license plate numbers on a sheet of paper and and putting that information into a database that can then be mines to identify patterns of behavior, associations between people, etc. Context, use, and scale all matter significantly
No.
Automating the system is ABSOLUTELY a difference in kind. The argument "it is the same thing" is reductionist beyond absurdity.
"Quantity has a quality all its own."
Scaling and automation is a difference in kind in every field, and especially in surveillance of a population. To deny it is to assert the Industrial Revolution, the Computer Revolution, and the Internet had no effect on anything.
A cop sitting by the road operating a speed trap time or radar/laser gun can trap enough speeders to moderate the traffic, and individual speeders get few tickets. Implementing the "same" thing with cameras everywhere and timing toll-booth arrival/departure times and issuing tickets automatically would result in the majority of drivers getting multiple speeding tickets every trip (just based on measured average speeds on most roads exceeding the posted limit).
Your example proves the opposite of what you say.
Having a cop personally observing and writing down license plates requires resources - a decision to prioritize those specific resources for that specific investigation on that day. It is a real decision to surveil people in that way. It means people will ONLY be surveilled in that way when it is important.
In contrast, constant, ubiquitous, and near-cost-free surveillance means people will be surveilled all day, every day.
What was once applied only to exceptionally serious crimes is now available to target any citizen for any petty crime. It enables exactly the kind of silent targeting for which every authoritarian government lusts — the appearance of law and order with the ability to target any specific "troublemaker" at will.
With such surveillance, there is no need for an authoritarian to make false charges or highlight a protest. Jack protests, they don't like it, just say "go after Jack". They go to the cameras, find a bunch of petty crimes, and prosecute. Jack now has endless trouble if not jail, and the regime carries on like nothing happened.
If, as you say, you don't understand why it is not different, stop being reductive, look at the larger system.
You have to look at this from a systems point of view. Yes, flock cameras individually only capture their immediate surroundings, but the emergent behavior of the system is a means to follow someone around wherever they go, which is already a no-no in our legal system without at least securing a warrant to do so. And, even securing a warrant for one individual does not give you the right to include everyone in an area, commonly referred to and struck down as dragnet surveillance.
Flock systems and their siblings are wrong and should not be tolerated.
IIUC courts have signaled in several cases that this distinction matters to them, which is good, because it's such a vast difference in degree that it arguably does become a difference in kind.
Police require a warrant to attach a GPS tracker to your car, or to directly obtain your cell phone location records. Why should access to networked ALPRs that compile an equivalently granular record of your movements be treated any differently? IIUC it was this exact line of reasoning ("detailed, encyclopedic, and effortlessly compiled" data equivalent to GPS tracking, for which a precedent had already been established) that supported the decision that now requires warrants for cell phone data (in Carpenter v. United States). Extending the same logic to networked ALPR data would seem obvious if we had the same SCOTUS.
A COMPUTER
CAN NEVER BE HELD ACCOUNTABLE
THEREFORE A COMPUTER MUST NEVER MAKE A MANAGEMENT DECISION
-IBM, 1979
This is actually a new pet hypothesis I've been testing against the various horrors beyond my comprehension that keep cropping up.
Would forcing an individual person into the loop and then holding them accountable - really, not on paper - help?
They may even converge to become the same thing.
Police officer can't practically write down every license plate at every intersection and recreate movement patterns of almost every citizen.
Laws are written with practical enforcement realities in mind. When those realities drastically change, the laws should be reassessed.
A warrant is for things that other people who are not police wrote down (or otherwise recorded). If a cop had been somewhere and seen it, then they saw it; but in actual fact, they are not everywhere, and so the state wants to get people who were there to turn something over.
What?
There is a lot of information privy to police that should not be accessible to anyone. This is such a ridiculous standard. I would want police to know where I live and contact information of my emergency contact for instance, but I wouldn't want that accessible to others.
> There’s been too many cases of police officers stalking exes, poking around the data for fun and such so it’s clear police cannot be trusted with the data without better court oversight.
There have been more cases of "someone broke into my house at exactly [time]. Can you track their license plate and track them down" that I'm willing to make that tradeoff. Those police that abuse their power should be brought to justice and its obviously against policies, but to simply remove their ability to effectively do their job is not the answer
Sounds reasonable, but most police departments will not do this, even if the data is available to them and running the query is easy.
They will tell you to file a report, preferably online, which will then be incorporated in local stats, and may also be useful in your interactions with your insurance company.
But they will not do anything to help your specific case.
Oddly, this was 100% commonplace before about 2000 or so, in the US at least. Every household got a free phone book from the phone company that contained the name, address, and phone number of everyone in town. I think you could opt out, but almost no one did.
It was incredibly handy and sometimes I still miss it. I'm not 100% sure why it was considered OK for so many decades but today would be considered a PII data leak, though I suppose it being limited to your local area vs. searchable by the whole world has something to do with it.
> There have been more cases of "someone broke into my house at exactly [time]. Can you track their license plate and track them down" that I'm willing to make that tradeoff.
I'm not, especially since anecdotally, police are generally unwilling to use these tools to solve petty crime anyway.
I want this data to require a warrant to access. Having said that, I agree that it should be open to everyone if warrants aren't required.
I've said this for years and I almost always get the "But stalkers!" pushback.
I think "But stalkers!" can be answered with applications to enable individuals to track their stalkers themselves. Since the police have no duty to protect I'd argue tracking a stalker yourself is probably a better solution anyway.
There are MANY cases where the government legitimately possesses personal information that could potentially cause harm if revealed, for operational as well as public safety purposes. Vehicle registration and drivers license records, for example.
This personal information is typically exempt from FOIA laws. I can't go FOIA vehicle registration records to look up where a certain driver lives, but the state and police officers do have access to that information.
A search involves access without consent. Police don't need a search warrant to perform a search with the consent of the owner. In the case of cell phone data the search is without the consent of the data owner (the phone company). In this case the municipality is collecting public-view data themselves, not without the consent of the collector, so there's no search warrant issue.
https://nlets.org/resources/blog/nlets-news-our-nationwide-l...
Arkansas': https://legislature.maine.gov/statutes/29-A/title29-Asec2117... > "Automatic license plate reader system" means a system of one (1) or more mobile or fixed automated high-speed cameras used in combination with computer algorithms to convert images of license plates into computer-readable data;
Maine's: https://law.justia.com/codes/arkansas/title-12/subtitle-2/ch... > "automated license plate recognition system" means a system of one or more mobile or fixed high-speed cameras combined with computer algorithms to convert images of registration plates into computer-readable data.
Vermont: https://law.justia.com/codes/vermont/title-23/chapter-15/sec... > “Automated license plate recognition system” or “ALPR system” means a system of one or more mobile or fixed high-speed cameras combined with computer algorithms to convert images of registration number plates into computer-readable data.
California's: https://law.justia.com/codes/california/code-civ/division-3/... > “Automated license plate recognition system” or “ALPR system” means a searchable computerized database resulting from the operation of one or more mobile or fixed cameras combined with computer algorithms to read and convert images of registration plates and the characters they contain into computer-readable data.
Just an FYI.
Willy-nilly search for relatives, lovers, love-interests, rivals, etc. would potentially be a fireable offence --like HIPAA violations. There is no technical reason there could not be technical controls preventing abuses.
So you're fine with 1984-ish type stuff as long as it's only used to enforce the will of the state and never used by the agents of the state for their own purposes?
Each use of the ALPR should have behind it an actual defensible case.
The lines start to get very blurry when dealing with things like private ALPRs and Ring/Nest etc. because they have the policy of if a LEO asks we provide (in the case of Ring LEOs have access to pretty much all doorbell cameras) but this is really problematic because although it's an attempt at good faith, they are essentially circumventing the legal process of acquiring this data for investigation since involving a judge is a cumbersome process.
But now we have a problem, LEOs are exercising essentially extrajudicial authority by having access to this data. The authority is provided to them by the law (hence why your average joe schmoe can't get this data) but they do not use the mechanisms provided to them to actually get that data. So all data should be provided to anyone regardless of status but if you don't have a lawyer and a reason in a civil case you get told to kick rocks
This is fundamentally a police officer problem. You make it a felony and a terminable offense. You make all or part of the Brady List public and this automatically places an officer on it. ALPRs are just one tool for a police officer to stalk someone, they could just as well park outside their house or place of work and follow them around or do other things. We could require warrants to get the ALPR data but we'd still have these jerks pretending in to protect and serve.
In my perfect world, if we had an Amber alert or we knew there was a particularly violent criminal driving a specific car with a specfic license plate, I think it would be a step forward if all of the information was made available quickly and there was a quick and safe capture. Judges can issue warrants pretty quickly when motivated. Likewise, if some officer is stalking his ex-wife or something, cutting off the license plates is a nice step but I'd rather him not be involved in law enforcement at all.
I'd love for these datasets to be fully audited, but I suspect industry will balk that the very use of it is proprietary.
This is how things get regulated. I'm still waiting for a data broker breach which exposes the particulars of congress. That would be quite the shakeup. I think it will happen eventually.
They could even run some AI over the request forms to spot unusual activity like an officer constantly requesting the location of their ex wife.
It is fully open and people can and do exactly that.
A warrant requirement is not a reasonable bandaid to consider allowing mass spying. There should be no mass spying by default.
A warrant requirement makes sense for something like the locations of customers on cellular networks, because, although it should be improved, it's been built into the tech.
When you make the optional choice to create mass spying, safeguards do not make it acceptable.
Also the cops would just get the private keys from the DMV anyway. It's all the same government.
I don't think that's been the case since 9/11. It's naive to assume the CIA, FBI and NSA don't have root access to every device and every account in existence, or couldn't get it if they wanted it, legally or otherwise. I don't think your local DMV is going to be the hard line keeping the feds from knocking at your door.
“In recent years, as artificial intelligence has advanced, Flock has added the ability to search for cars based on their make, type, color, or unique details, such as bumper stickers or visible damage.” So TOTP license plates is not enough.
IRL we will probably need more mature solutions - legislation, regulation etc. At this point we know the tech can't really be contained. It'll be all-seeing, all-knowing and super cheap. Just as the source/link describes it. So the only way is to have actual adults working in law enforcement.
> I think cameras in all public spaces are going to happen. Imagine Ring comes out with a nicer camera system for homeowners....
Indiscriminately filming people in public places is illegal some places, e.g. Germany. Allowing the creation of large networks of cameras surveilling public places is a choice.
The right of the people to be secure in their persons, houses, papers, and effects...
Who is "their" here? In terms of property rights it's the people who own those digital "papers". The individuals who that data is about do no maintain or control that data, and could not destroy it, meaning they do not functionally have property rights over it. If I write in my notebook that you have blonde hair, the notebook is still my property. There isn't anything I could write about you in it that would make it yours (other than maybe "I hereby give this notebook to Joe Bloe").Attempts to interpret the Constitution otherwise are, IMHO, attempts at good policy, but unstable as law. So we should fix it either by giving people property rights to that data (so that they can destroy or change it without permission) or to explicitly require warrants for access to PII owned by third parties.
..."and particularly describing the place to be searched, and the persons or things to be seized."
It was an attempt to secure privacy. "Their" means an individual, a person. Essentially, you control what you control, and do not need to give up this control unless there is suspicion of crime.There are also the rights of the people to peaceably assemble -both publicly and privately-, peaceably speak publicly, and peaceably bring their grievances to the various governments that govern them. All of those rights interact with regulation of the things we're talking about here... it's not just the 4th amendment that's relevant.
Go against this, and filming your kids baseball game becomes a legal nightmare.
Yep. And dragnet surveillance has (pretty much?) always been illegal in the US... but it takes the courts an awfully long time to notice the new dragnets the cops set up.
For example, despite the fact that the third-party doctrine says that cops can just walk up and get any ordinary business records someone you do business with has created about you, courts continue to notice and declare illegal new ways in which naive application of that doctrine creates dragnets.
I find this attitude I find kind of tiring. Gosh it’s just sooo hard to figure out the difference between Flock Safety and Big Bill’s Little League Sports Photography. It’s actually very straightforward to determine the difference between these two things. So easy, an idiot could do it. Or a judge.
We lost a lot of strong privacy rights we had with landlines when we shifted to cell phones.
We're actually slowly creeping into pre-crime territory. You could have AI searching for possible pre-crime candidates based on unknown identity in the area, disparate pattern to usually movements, etc.
It's better to raise the voice now for you guys than to say sorry later.
Is it legal for a private entity to do the same with their owned space (like a plaza or mall or office tower)?
Focusing on license-plate-readers seems like car-brain is causing the author to miss the forest for the trees.
(I am aware that the UK has a less-than-stellar privacy track record... but nonetheless it's curious that for this particular technology, as opposed to the Online Safety Act, there's such a difference.)
[1] https://www.404media.co/clapping-is-a-first-amendment-right-...
Our police overlords are not so polite.
In the UK there's severe limitations on freedom of speech, which would never be accepted in the US. The countries have very different values.
Sure, but those are just as controversial here as in the US, in a way that ANPR is a non-issue.
The US has also shown that the probability of someone being held accountable for massive abuse of power is essentially 0. This also means that the main disincentive for abusing power (getting caught and punished in some way) is a moot point.
People generally don't object to technology being used to fine mass shooters, or terrorists, or bank robbers. They do object to the same technology being used to stalk women that Texas thinks might be trying to get an abortion, or ensure that minorities stay out of the "white neighborhoods". One of these examples is a real thing, the other is what people are (reasonably) afraid of.
The US had only about a hundred years to get used to bending over and taking it from a government that doesn't really represent the people whereas the British have just shy of a thousand. So of course the US is more uppity.
Now is not the time to be giving more power to the executive or its policing functions.
In my conversations with law enforcement (mostly at management level, chiefs of police), all of them have had reasonable-sounding objections to a warrant requirement for a search, but zero of them have been able to come up with a reason why a case-or-CAD ID requirement isn't workable. Generally, they argue that in practice obtaining a warrant can be too onerous in time sensitive situations, and can be harder to obtain than the public realizes. Two popular examples are in kidnappings (time sensitive) and missing persons (difficult to obtain).
A case number or CAD ID however simply requires that the details of either a public call for service or an active investigation are associated with the historical search. It closes the door on officers' hobby searching.
Andrew's blog post does note the problems with oversight, which also match my experience, so this isn't a perfect fix. But it will go further in conversations with law enforcement for people that are trying to thread the needle on making "safe" mass surveillance.
(I am personally opposed to mass surveillance in all its forms, but arguing only from that position pretty much immediately excludes me from policy discussions.)
I did not want to go into too many technical details on the post -- I think you could do an AI audit at the point in time of the search query to prevent people putting in junk cases. That said I believe there will always need to be third party audits at a minimum.
Part of the issue is policies on paper are not effectively enforced. So people saying "just have policy X to prevent abuse" is a non-answer.
I wrote the post mainly because people arguing for limited data retention I think is bad for both sides -- it neither protects civil liberties and simultaneously makes it harder for long term criminal investigations.
The thing about CAD/case IDs is that it makes the use of junk cases in audit trails more detectable vs. the current situation.
Third-party audits would be great, but I haven't been able to find an ideal third party to do the auditing. Locally, police commission groups quickly got co-opted through political processes into being both toothless and extremely deferential towards the police department. I wouldn't trust state auditors any more than local auditors. That's why we pushed to force audit logs to be made publicly accessible in SB1516 6(3)(a): https://olis.oregonlegislature.gov/liz/2026R1/Downloads/Meas...
> Part of the issue is policies on paper are not effectively enforced. So people saying "just have policy X to prevent abuse" is a non-answer.
Policies on paper are where you start. I wholeheartedly agree that they are not by themselves sufficient, but they have to exist, and to that end, you want the strictest possible policies that are politically achievable. I don't believe that a warrant requirement is politically achievable.
We had several deep conversations with ACLU on data retention limits. Data retention limits were one of the things they fought hardest for in this state. We supported that, but focused more of our energy on a different aspect (which we didn't succeed at, unfortunately). ACLU's point of view is that longer data retention makes it easier to profile the movements and activities of politically sensitive groups. It's true that it does, but ALPR vendors' ability to directly access and control the data means that there are numerous trivial workarounds for targeting any demographic or political group, regardless of data retention limits.
I remain of the opinion that these systems simply don't need to exist at all, which makes the answers to a lot of these questions a lot easier. Violent crime has overall been trending downward for a long time, we live in one of the most peaceful societies in human history, we already know how to reduce property crime and crime directly related to poverty, and roving armed gangs are not a sensible immigration policy. We're twisting ourselves in knots trying to figure out how to make an inherently unsafe technology safe to meet a need that we don't have.
Flock exists because YCombinator and subsequent investors saw an opportunity to use public grant money to pay to bootstrap the collection of an enormous amount of really valuable data on Americans.
I wonder if people who feel this way will feel safer? In this scenario, you have a Ring camera system observing your entire property. Do you feel safer if someone comes onto your property and triggers an alarm? What if it turns out it's just a kid coming over to grab a stray frisbee? What if your neighbor noticed something needed a quick fix (say you left a can of paint open or something similarly benign) and wanted help in a neighborly way without first checking to see if you were home?
I guess we just take for granted that we live in a low-trust society. But we take that for granted at our peril, because the fear of a low-trust society is actively being exploited by people who want to sell individuals, businesses and municipalities the means to further erode that trust.
https://github.com/ryjones/alprs
Using more vibe code:
https://github.com/ryjones/platescan
The bar is low.
Access control (warrant) doesn't prevent a breach, and the system is not architected in a way to prevent internal abuse. The best way to prevent the abuse of data is to not collect or store it at all.
Why should it be possible for my bits be scooped up and sold for profit against my will.
It's a new paradigm. Flock is the first to blatently collect and sell public whereabouts for private gain.
Conflating this with insurance is a interesting take.
Also, the notion that I have a choice to not have a car is absurd. I'd starve. And, even if I could walk around are traverse my town with only a bike or walking, I'm still sucked into a harddrive against my will by these cameras.
1) remove the hazard
2) replace the hazard with something less hazardous
3) isolate the hazard (guards, cages etc)
4) administrative controls (procedures, training, warning, etc)
5) PPE
Implementing some kind of judicial review for these panopticons is something like 4) in the hierarchy. It would be a good thing to have, but we can go far further. Why do we need this shit? Oh what so someone’s car doesn’t get stolen a few times per year? I think my values are in line with the founding fathers and most Americans when I say I would gladly give up a little bit of safety to not have a spy camera trained on me 24/7.
I would like more removal and less procedural controls. The cops cannot abuse a system that does not exist.
It seems that would easily impede a lot of abuse and it’s straightforward to believe that historical data is rarely so urgent as to not require a warrant.
A matter of defining historical as a sufficiently old enough thing but that seems feasible.
Why couldn't they get a warrant if it's an ongoing issue? It should be really easy, and warrants like that wouldn't take a long time to get usually.
Very reasonable not to, of course, but it helps me adjust my understanding of things. And yes, if a warrant is a 10 min process at p95 from call receipt to warrant acceptance then that certainly allows for things like "this car was stolen in an armed robbery 20 mins ago; we'd like to track it through the city" without too much concern, and I would switch to requiring such an SLA[0] on warrants combined with a requirement on warrants that can be rescinded if the SLA is violated.
0: strictly nonsensical here, but I think you get the picture
Just to clarify, the timelines you describe are from experience, knowledge, or theorycrafting?
The accused has comparatively no rights when an bureaucrat is shaking them down and the accused is often a business rather than an individual it's easy to have sympathy for. Flock could've run their racket for many years, got much praise from the useful idiots, really gotten their system integrated and entrenched, if they'd have chosen that route.
Their mistake was believing in their own bullshit. They thought they could make it cheaper to solve crimes (at great cost to everyone's rights of course, but they thought this was acceptable) and make things better (or at least their definition of it). If only they had been slightly scummier and instead set out to help municipalities collect civil fines they probably could have gotten away without scrutiny.
There are lots of vids of people claiming that, generally low information sovcits. But it makes for great window smashes.
I know it's unpopular but I went from not supporting these sorts of systems to embracing them after seeing the positive effects in China.
For crimes that depend on anonymity, theft, assault, hit-and-runs, vandalism, illegal parking, etc., surveillance changes the calculation because the offender expects a higher or even a near certain chance of being identified/caught in China. I think this is a good thing. I also see no issue with someone breaking the law and receiving a ticket almost immediately.
With all systems, it comes down to the design. What sort of oversight is there, how long is footage stored, can it be used for specific crimes or expanded later, and are there mechanisms to correct false identification.
Done right, these systems work well. I would be happy to live in a society where street crime is rare enough that I can leave personal property anywhere, like a bike, without constantly worrying about theft. I think many fears about these systems come from dystopian science fiction and assume the worst possible implementation, rather than recognizing that technology can be designed with strong safeguards.
Why did they need flock?
Uhh, because getting safer is still better? Why the hell does the relative ranking matter?
Reliable studies have shown that increasing the severity of punishment doesn't deter crime, but increasing the chance of being caught does. Cameras directly address the later. You'd have to be a total idiot to steal a car these days.
https://www.nytimes.com/interactive/2019/04/04/world/asia/xi...
https://en.wikipedia.org/wiki/Social_credit_system
https://www.csis.org/analysis/old-friends-new-calculations-r...
https://en.wikipedia.org/wiki/2020_Hong_Kong_national_securi...
Mass Surveillance deters crime and makes the job of law enforcement easier. I'm happy to live with Mass Surveillance because I don't think the drawbacks of having it aren't that bad, there are some benefits to me, and I trust institutions to implement safeguards.
Now replace Mass Surveillance with any of the following, and I think the your argument is the same:
- Warrantless Searches
- Giving Police the ability to convict in the field
- Permanent and mandatory position tracking for all citizens
- Required public identities for all online activityAny police state can absolutely achieve a low rate of crime: both those crimes that even those of us that embrace individual rights want to see stopped but also those crimes that us liberal types would consider exercise of rights.... but are definitely crimes in China.
The problem is, you can't stop the real, mutually agreed crime with tools like this without endangering the elimination of legitimate individual rights.
In more liberal societies, this means we have real barriers for evidence collection and usage which absolutely let some universally recognized bad guys get away... because those barriers help ensure that the law doesn't become a tool against the merely politically inconvenient opposition members who properly should be able to speak out against the powerful.
If you had a perfectly objective government filled with dispassionate people dedicated to their legitimate role of protecting the rights of the citizenry... perhaps there wouldn't be any issue. But when you have people that decide to turn their opponents into criminals only because of their opposition or questionable loyalty.... No thank you... you can stay in China if that's the kind of society you're willing to accept.
There are civilian enterprise uses of ALPR. Where do they fall in this? I don't even mean for mass data collection or even for parking enforcement. I'm thinking of like various car washes where they offer monthly memberships and their car wash portal system has plate recognition to tie your membership to your car. Or other enterprise access control applications where the ALPR pops the gates open instead of RFID tags.