The Camera You Fear and the Camera You Bought

The Camera You Fear and the Camera You Bought
There is a special kind of civic theater in which a neighborhood can work itself into a moral panic over a pole-mounted license-plate camera while the same neighborhood’s living rooms, driveways, windshields, pockets, and faces are already wired for recording. The latest object of that theater is Flock Safety: a network of automated license-plate readers used by police departments and private customers, now numbering well over 100,000 devices and generating billions of plate scans a month. Communities have canceled contracts. Cameras have been vandalized. Advocacy groups map the poles like they were missile silos. Bipartisan politicians have piled on. Some of the complaints are serious. Most of the surrounding rhetoric is unserious.
The case against treating Flock as the apocalypse is not that public surveillance is harmless. It is that the people shouting loudest about it have already volunteered a far more intimate surveillance architecture to private companies, then acted shocked when governments use the same architecture. That is not principled civil libertarianism. It is a tantrum about the camera they did not choose, combined with amnesia about the cameras they did.
Start with the device almost everyone already owns. The modern smartphone is a location beacon, microphone, and camera that follows its owner into the bedroom, the doctor’s office, the protest, the church, and the motel. Apps request location and camera access as a condition of convenience. Photos carry GPS metadata unless the owner bothers to turn it off. Advertising identifiers leak movement even when “personalized ads” are disabled. Americans tell pollsters they worry about being tracked, then install the next app anyway. Researchers have a name for this split between stated anxiety and actual behavior: the privacy paradox. It is not a theory. It is the operating system of consumer life.
Then came the home. Ring and its competitors turned the front porch into a subscription camera network. Tens of millions of households pointed lenses at sidewalks, delivery drivers, neighbors, and their own children. Police partnerships followed as night follows day. Ring has worked with thousands of local public-safety agencies. Officers request footage through community tools. Amazon has also handed over recordings in emergency cases without the owner’s prior consent, and it complies with warrants and subpoenas like every other large platform. People bought the doorbell to catch package thieves. They also built a privately owned street-level camera grid and then expressed horror that law enforcement might ask to look at it.
Now the face. Meta’s Ray-Ban smart glasses sold millions of pairs in a single year. They look like ordinary sunglasses. They record video and audio. They feed images into an AI stack. Privacy advocates warned, correctly, that a camera on a face is harder to notice than a phone held at arm’s length. Users still lined up. Some disabled or obscured the recording light. Reports of covert filming followed. Meta has discussed more aggressive “sensing” prototypes. Google and others are entering the same market. The public that cannot abide a city pole photographing the rear of a car on a public road is eager to strap a networked camera to its own head and walk into restaurants.
This is the point at which opposition to Flock, as currently practiced in the streets, starts to look less like a theory of liberty and more like a costume. A Flock camera typically photographs a government-issued plate on a public roadway. Courts have long treated that kind of observation as different from rummaging through a house. The company’s own description is point-in-time capture of vehicle characteristics, not a name, Social Security number, or face print, with default deletion measured in days or weeks unless a case holds the record. That is not a clean bill of health. Retention, sharing settings, national lookup networks, and sloppy agency controls have produced real abuses: officers stalking former partners, searches tied to abortion investigations, protest-related queries, and messy federal access through local partners. Those are arguments for warrants, audits, short retention, and tight sharing rules. They are not arguments that the device is uniquely demonic while the phone in your pocket is a lifestyle accessory.
The moral math does not work. A municipal ALPR sees a car leave a public street. A phone company, an app vendor, a cloud photo locker, a car with cabin cameras, a doorbell, and a pair of AI glasses can reconstruct where you slept, whom you met, what you said, what you bought, and what you looked at. The government does not need Flock to enter that world. It already buys commercial location data. It already serves legal process on Google, Meta, Apple, and Amazon. It already uses programs and statutes—Section 702, the CLOUD Act, ordinary warrants and subpoenas—that pull private-platform records into official databases. The person who will not tolerate a plate reader but will dump a decade of messages, photos, and location history into a corporate cloud is not defending a principle. He is picking the villain that photographs strangers instead of the one that flatters him.
None of this requires pretending Flock’s rollout has been clean. Cities have canceled contracts after discovering sharing settings they did not understand. Officers have been charged or forced out for using the system as a personal tracking toy. Immigration enforcement access through local partners has driven liberal cities and some conservative ones to the same exit. Those facts belong in the debate. What does not belong is the pretense that yanking a few thousand poles restores a private society while the rest of the sensor stack remains in place and expanding. Sabotaging a camera on a lamppost is easier than deleting your account, reading a privacy policy, or demanding a statute. That is why it is popular. It is also why it is a joke.
The better fight is not “cameras bad, phones fine.” It is a single demand aimed at both the state and the firms that already hold the real dossier: limits on collection, limits on retention, limits on sale, limits on compelled and informal sharing, audit trails that actually get read, and penalties that land on people who treat a database like a toy. Until that is the program, the anti-Flock crusade will keep mistaking a visible pole for the system.
The panic is new. The bargain is not. Every generation treats the latest recording machine as a unique insult to dignity, then absorbs it, then acts as if the next machine appeared from nowhere.
When photography left the studio in the late nineteenth century, it was denounced as a weapon. Hidden “detective cameras” were used to catch people entering saloons. Respectable citizens discovered they could be fixed in an image without posing for a portrait. The outrage was real. So was the adaptation. Within a generation the snapshot was domestic furniture. The phonograph and the telephone produced the same cycle: first a scandal about captured speech, then a utility so ordinary that people forgot they had ever argued about it. Wiretapping followed the wires. In 1928 the Supreme Court, in Olmstead, said a tapped telephone call was not a Fourth Amendment search. Congress and later courts spent the next half-century walking that holding back, then walking it forward again. Title III of the 1968 crime bill banned private wiretaps and authorized government taps with a warrant. J. Edgar Hoover publicly called wiretapping unethical and privately used it anyway, including against Martin Luther King Jr. The pattern is stable: technology first, law late, hypocrisy constant.
study.
After 9/11 the United States stopped pretending the old bargain still held. The Patriot Act widened domestic collection. The NSA built programs that vacuumed telephony metadata and, through PRISM, obtained data from the major internet firms. Edward Snowden’s 2013 disclosures did not reveal that government wanted records. They revealed that the records already lived at Apple, Google, Microsoft, Facebook, and Yahoo, and that the state had built a legal and technical on-ramp to them. Companies later demanded the right to publish request numbers. They did not stop collecting. They could not. The business model is the dossier.
That is the part the Flock debate keeps skipping. A city pole that photographs a plate is visible, municipal, and therefore available as a mascot. The larger pipeline is contractual and mostly unseen. Section 702 of FISA lets the government compel U.S. providers for foreign-intelligence collection without an individualized warrant targeting the American who happens to be on the other end of the communication. Analysts can then query the resulting databases. The CLOUD Act of 2018 confirmed that a U.S. company can be forced to produce data it controls even if the servers sit abroad, and it authorized executive agreements so foreign partners can go to those companies directly. Transparency reports from Google, Meta, and Microsoft show request volume rising for years. That is not a conspiracy theory about a secret camera company. It is the ordinary legal process attached to the cloud accounts people create before breakfast.
When process is inconvenient, the government shops. Federal agencies have purchased commercially available location data derived from phone apps: the same GPS crumbs users drip in exchange for maps, weather, games, and “free” services. After Carpenter v. United States (2018) held that police generally need a warrant for a week of cell-site location information from a phone company, agencies leaned on the claim that buying the same facts from a broker is different from compelling them from a carrier. The result is a loophole with a price list. A license-plate camera on a public road is a crude instrument next to a marketplace that sells movement histories tied to advertising IDs. If the objection is “they can reconstruct my life,” the broker file is the better exhibit.
Look abroad and the American tantrum looks even smaller. The United Kingdom has lived for decades as a CCTV society. Estimates put the national camera count in the many millions; London routinely ranks among the most filmed cities in the democratic world. Britain also runs automatic number-plate recognition at a scale that makes a suburban Flock deployment look like a science-fair project. The public argument there is not “remove every camera.” It is who may look, for how long, and under what code. That argument is often lost. It is still the adult version of the fight.
China is the warning, not the analogy people think they are making when they point at a black pole in Ohio. Chinese cities pack cameras at densities the West has not matched, then wire them to identification systems and public-security databases. Firms are legally obliged to assist the state. That is a regime problem first and a hardware problem second. Copying the hardware without copying the party-state does not automatically produce the party-state. Pretending that it does is how a liberal democracy talks itself out of ordinary policing tools while leaving the commercial stack untouched. The European Union, by contrast, treated the commercial stack as the main event. GDPR starts from the premise that images, location, and identifiers are personal data, demands a legal basis for processing, and puts real fines on companies. It is clumsy, expensive, and sometimes theatrical in its own way. It is also aimed at the right mountain. The United States still has no comprehensive federal privacy statute of that scope. It has a patchwork, a trial bar, a few state laws, and a talent for screaming at the most photogenic sensor.
journals.
East Germany’s Stasi is the other lazy comparison. The Stasi ran on informants, files, and a state that recognized no private sphere the party did not grant. It did not need citizens to buy the microphones. Contemporary America runs on the opposite incentive: citizens buy the sensors, click “agree,” upload the photos, enable the assistant, and then describe the resulting archive as something done to them. The archive is still dangerous. A jealous officer, a sloppy fusion center, a future administration with different enemies, a broker breach, a subpoena for “the whole account”—all of that is real. So is the fact that the archive was assembled, in large part, by people who wanted next-day delivery, turn-by-turn directions, and glasses that tell them what they are looking at.
History does not say surveillance is fine. It says societies do not get to keep the machine and uninvent the record. They get rules, or they get improvisation. The United States has preferred improvisation: collect first, litigate later, reform after the leak. Flock is being forced through a public gauntlet because it is bolted to a city contract. Google Photos is not, because it is bolted to a user. That difference is politically convenient. It is not morally impressive.
If the goal is to keep the government from assembling a movable map of private life, the map is already drawn in corporate ink. The serious project is to put the same handcuffs on the buyer and the seller of that ink. The unserious project is to congratulate yourself for pulling down a pole while the phone on the kitchen counter continues its shift.
The useful conclusion is not that Flock cameras are sacred, or that police should get an unsupervised national dragnet because consumers are sloppy. The useful conclusion is that the present campaign is pointed at the wrong control panel. A society that rushes to buy phones, doorbells, cabin cameras, and AI glasses, then dumps the resulting life-log into firms that already answer government process, does not get to call itself a resistance movement because it hates a pole. It gets to call itself a customer with a slogan.
Misuse of Flock systems is not imaginary. Officers have used plate networks to stalk former partners. Departments have run searches that alarmed cities after the fact. Sharing settings have been broader than local officials understood. Federal agencies have reached local data through partners rather than through a clean, publicly debated statute. Those are reasons to write rules. They are not reasons to pretend that disabling one vendor restores 1975. Yanking cameras while leaving commercial location markets, cloud photo lockers, and warrantless broker purchases in place is like boarding up a window and leaving the front door off the hinges.
The better program is boring, which is why it loses to vandalism and city-council spectacle. It has a single target: the use of private information, whoever holds it.First, collection. Public ALPR should be limited to public roadways, without facial recognition bolted on by default, and without “hot lists” that any bored administrator can load for sport. Consumer devices should not hide cameras in ordinary eyewear without an unmistakable, hard-to-defeat recording signal and a real off switch. “We might test always-on sensing” is not a feature. It is a confession.
Second, retention. Data that is not evidence should die on a short clock. Flock’s own retreat from month-long default storage toward days, with a separate evidence hold tied to a case number, is the correct direction if it is real and auditable. The same logic belongs in the cloud. There is no serious privacy politics that demands a police plate image vanish in a week while a platform keeps a decade of precise location, private messages, and face-tagged photos because the user once wanted a shared album.
Third, access. Government queries of ALPR networks, phone records, cloud accounts, and doorbell footage should require a documented predicate, and for movement histories that reconstruct a person’s life over time, a warrant. Carpenter already pointed there for cell-site data. Congress should close the broker loophole that lets an agency buy what a judge would have to approve if the carrier were asked directly. Informal “can you just run this plate for us?” arrangements between local systems and federal agencies should be treated as what they are: a way around the argument the public was told it was having.
Fourth, sharing. Agencies should own their data and should not discover, after a newspaper request, that two thousand other organizations can search it. One-to-one sharing for a live case is policing. A national lookup setting flipped on by default is a different animal. Private platforms should publish, in plain numbers, how often they produce content versus metadata, how often they are gagged, and how often they hand over data under emergency exceptions. Ring’s history of emergency disclosures without owner notice is a reminder that “the customer is in control” is a brochure sentence, not a description of the legal stack.
Fifth, audit and punishment. Every search needs a name, a time, a case number, and a reason that a supervisor can read. Flock’s audit tools have already caught at least one officer who treated the system as a personal tracker. That is an argument for mandatory audits, not for the fantasy that a tool with no logs is more moral because it is harder to catch the thief. People who query an ex, a political rival, or a medical trip should lose their access and, when the facts support it, their badge. Companies that sell movement data with a wink should face penalties that exceed the revenue from the sale.
Sixth, one statute for the whole pile. The United States still treats privacy as a pile of sector rules and privacy policies no one reads. Europe’s GDPR is not a sacred text, and it has not abolished cameras. It does force the argument onto data as such: purpose, minimization, legal basis, deletion, and fines that a general counsel cannot laugh off. A federal American statute that covers government databases and commercial dossiers together would do more than a thousand “Deflock” maps. Without it, activists will keep winning symbolic cancellations in Austin or Seattle while the same facts migrate into another vendor, a broker, or a phone backup.
The objection writes itself: public cameras are involuntary; a phone is a choice. That distinction matters. It does not finish the sentence. The phone is only a choice in the way electricity is a choice. The resulting file is still available to the state by law, to brokers by contract, and to whoever steals it. A politics that honors only the involuntary camera will spend its life tearing down the one sensor citizens can see while blessing the ones they pay for. Authoritarian systems fuse the two on purpose. Democratic systems are supposed to separate them with paper: warrants, retention limits, and penalties. Paper is less photogenic than a cut cable. It is also the only method that has ever lasted.Unite around that, or keep performing. The performance is easy to understand. A Flock pole is a perfect enemy: public, ugly, official, and local enough to yell at on a Tuesday night. Meta, Google, Amazon, Apple, the data brokers, and the statutes that already pipe their archives into government offices are larger, lawyered, and mixed up with products people like. So the energy goes to the pole. That is not courage. It is displacement.Demand the guardrails. Put them on the city contract and the terms of service. Put them on the detective’s login and the broker’s storefront. Put them on the glasses as well as the intersection. Until then, the loudest opposition to Flock will remain what it looks like from a short distance: a country terrified of being seen by a government camera, and impatient to be seen by every other kind.








Comments