The infrastructure of being watched

You can’t turn off the cameras — even the ones you bought.

Outside, a network of automated cameras and sensors records where you go and keeps it for later. Inside, the devices you paid for do the same thing to your living room. This is how modern surveillance actually works — who runs it, how well they secure it, and whether it does what it promises.

Outside · the mechanism

A camera used to be a camera. Now it’s a searchable memory.

The change that matters isn’t the lens. It’s that what a camera sees now flows into a database that is retained, networked, and searchable months later.

Four kinds of sensor are spreading fastest. Automated license-plate readers — the dominant vendor, Flock Safety, runs more than a hundred thousand of them — photograph every passing car and log where and when it was seen. Face-recognition systems match people against databases. Acoustic sensors, originally sold to detect gunshots, are being pointed at human voices: in October 2025 Flock announced it would expand its microphones to listen for “human distress,” including screaming.1 And camera-equipped drones are increasingly launched as first responders.

Outside · what is being deployed

Four kinds of sensor, four different records.

Plate readers
Where your car was, and when
Photograph every passing car and log the sighting. Flock Safety alone runs more than a hundred thousand of them.
Face recognition
Who a face matches
Compares people against databases of stored faces.
Acoustic sensors
What was heard
Sold to detect gunshots. In October 2025 Flock said it would expand its microphones to listen for “human distress,” including screaming.
Drones
A camera that follows
Camera-equipped, and increasingly launched as first responders.
Sourced in note 1 below.

Any one reading is mundane. The problem is the aggregate. Oakland offers an unusually clear picture, because its police department publishes the numbers: in 2025 its 293 readers recorded more than 638 million license-plate scans, which generated about 1.1 million “hotlist” alerts — and only a fraction of those led anywhere.2 That is the real mechanism: a running record of the movements of an entire city, almost all of it belonging to people no one suspects of anything.

Oakland, California · calendar year 2025

638 million scans produced 1.1 million alerts. Almost every scan belonged to nobody’s suspect.

638,000,000
license-plate scans recorded by 293 readers
1,100,000
“hotlist” alerts generated — 0.17% of all scans
That hairline is the entire alert total, drawn to the same scale as the bar above it. Only a fraction of those alerts led anywhere at all.
293
readers deployed
~2.2 million
scans per reader, per year
1 in 580
scans that raised any alert
Oakland Police Department published reporting, note 2 below. The last two figures are arithmetic on the first two.

Outside · security

The people collecting this can’t reliably keep it safe

A system that records everyone’s movements is only as trustworthy as its weakest camera — and the cameras have not held up well to scrutiny.

Across late 2024 and 2025, independent researchers catalogued a long list of security flaws in Flock’s devices — one white paper documented 51 findings, 22 of them assigned formal vulnerability identifiers.5,6 A musician-turned-researcher, Benn Jordan, working with others, showed that with brief physical access to a roadside camera it could be fully compromised, and reported that some older units ran outdated software with unencrypted storage.6 Worse, dozens of cameras were found sitting on the open internet with no password at all — live feeds of parking lots, arguments, and children in parks, viewable by anyone who knew where to look, many of them the type of camera that tracks people rather than plates.7

Flock disputes the framing. The company says it has registered the reported vulnerabilities with the national CVE database, continues to publish findings, and maintains that none of them undermine its customers’ public-safety work.5 It initially argued the attacks required physical access and inside knowledge; researchers responded that publicly mounted and cloud-connected cameras showed the same weaknesses.6 Lawmakers have since asked the Federal Trade Commission to investigate, pointing to stolen customer credentials and the absence of mandatory multi-factor authentication.1 The through-point is simple: this is a database of where people go, and it has repeatedly turned out to be less secure than the companies selling it claim.

Independent research · late 2024 through 2025

A record of where people go, held on hardware that keeps failing review.

51
findings in one white paper
22
assigned formal vulnerability IDs
Dozens
cameras online with no password
What researchers reported
  • Brief physical access to a roadside camera was enough to fully compromise it.
  • Some older units ran outdated software with unencrypted storage.
  • Cameras sat on the open internet with no password — live feeds of parking lots, arguments, and children in parks.
  • Lawmakers asked the FTC to investigate, citing stolen customer credentials and no mandatory multi-factor authentication.
What the company says
  • The reported vulnerabilities are registered with the national CVE database, and findings continue to be published.
  • None of them undermine customers’ public-safety work.
  • The attacks required physical access and inside knowledge — though researchers replied that publicly mounted, cloud-connected cameras showed the same weaknesses.
Sourced in notes 1, 5, 6 and 7 below.

Outside · misuse and error

A tool this powerful gets used for more than catching criminals

Two things follow from mass collection: the data gets searched for purposes far from the original pitch, and the systems make mistakes with real consequences.

On the misuse side, the Electronic Frontier Foundation obtained records of more than 12 million searches run by over 3,900 agencies in less than a year, and found searches tied to political protests, searches targeting Romani people, and searches related to women seeking reproductive healthcare.1 Reporters separately documented Texas officers searching plate data to find a woman who had traveled for an abortion, and federal immigration authorities reaching one state’s data in apparent violation of its privacy law — enough to trigger a state audit.1,4 These systems have also been misused by individual officers to track specific people, including a documented case we cover on our advocacy page.

Records obtained by the Electronic Frontier Foundation

12 million searches by 3,900 agencies, in under a year.

12,000,000+
searches run
3,900+
agencies running them
Under 12 months
period covered
Found in the recordsEFF review
Searches tied to political protests. Searches targeting Romani people. Searches related to women seeking reproductive healthcare.
Abortion travelTexas
Reporters documented officers searching plate data to find a woman who had traveled for an abortion.
Immigration accessone state
Federal immigration authorities reached the state’s data in apparent violation of its privacy law — enough to trigger a state audit.
Sourced in notes 1 and 4 below.

On the error side, face recognition has contributed to more than a dozen known wrongful arrests, and the pattern is disturbing: nearly everyone misidentified has been Black, and the technology is measurably less accurate for darker skin.9,10 One man was handcuffed in front of his children; a woman was interrogated while eight months pregnant; another man was jailed over a holiday weekend for a crime in a state he had never visited.9 A recurring flaw makes it worse: police often build a photo lineup around the algorithm’s pick, so a witness “confirms” the same face the machine chose.9 Departments reply that a match is only an investigative lead and that some, like Detroit, have tightened their rules — a fair point, except the record keeps showing the lead treated as proof.9

The error side · how a bad match becomes an arrest

The lineup gets built around the algorithm’s pick.

Step one
The software picks a face
A face-recognition system returns a candidate out of a database.
Step two
The lineup is built around it
Police often assemble the photo lineup around the algorithm’s choice rather than independently of it.
Step three
The witness confirms the machine
A witness picks the same face the software chose — and the lead starts being treated as proof.
Departments reply that a match is only an investigative lead, and some, like Detroit, have tightened their rules.
A fair point, except the record keeps showing the lead treated as proof.
A dozen +
known wrongful arrests
Nearly all
of those misidentified were Black
Less accurate
measurably so, for darker skin
Sourced in notes 9 and 10 below. Documented cases include a man handcuffed in front of his children, a woman interrogated while eight months pregnant, and a man jailed over a holiday weekend for a crime in a state he had never visited.

Outside · the evidence

Does it actually work? The honest answer is: unclear

The case for these systems deserves a fair hearing, and it has real points in its favor. It also has less evidence behind it than the marketing suggests.

Start with the strongest version of the argument. Flock’s own analysis estimates its network helps solve roughly 700,000 crimes a year — on the order of a tenth of reported crime nationwide.8 Police can point to concrete results, including cameras that helped identify a suspect in the killings of three women; and some civil-rights voices, such as an Oakland chapter of the NAACP, argue that an automated read is less biased than an officer’s discretionary decision about whom to stop.11 None of that should be waved away.

But the independent evidence is thin and mixed. A review of the research concludes there is little empirical support for the claim that plate readers reduce crime.3 A study of a large plate-reader expansion in Atlantic City found no clear drop in violent crime overall — some associations with fewer shootings and thefts, but with the authors warning that other factors are hard to rule out.4 And the yield is lopsided: recall that Oakland logged 638 million reads to produce about 1.1 million alerts, only a sliver of which mattered, and even the police there describe the cameras as “one element,” not the cause of any decline.2 The distinction that matters: “this camera helped solve a case” and “recording everyone, all the time, is justified” are different claims — and only the first is well-supported.

Outside · the evidence, both directions

The strongest case for the cameras, next to the independent research.

The case for
  • Flock’s own analysis estimates the network helps solve roughly 700,000 crimes a year — on the order of a tenth of reported crime nationwide.
  • Cameras helped identify a suspect in the killings of three women.
  • An Oakland chapter of the NAACP argues an automated read is less biased than an officer’s discretionary decision about whom to stop.
The independent evidence
  • A review of the research finds little empirical support for the claim that plate readers reduce crime.
  • A study of a large expansion in Atlantic City found no clear drop in violent crime overall, and warned other factors are hard to rule out.
  • Oakland police themselves describe the cameras as one element, not the cause of any decline.
These are two different claims, and only one of them is well-supported.
“This camera helped solve a case” is not the same claim as “recording everyone, all the time, is justified.”
Sourced in notes 2, 3, 4, 8 and 11 below.

Inside · the turn

The same pattern now lives in your house

The devices you bought run the identical play: they record, they phone home, and you don’t control what happens next.

Take the robot vacuum — a useful worked example because so many now ship with a camera, microphones, and a permanent connection to the maker’s cloud. In 2024, security researchers at the DEF CON conference showed that popular Ecovacs models could be taken over through a weak Bluetooth and PIN design, letting an attacker switch on the camera and microphone from outside the home, with no indicator light — and even delete the spoken “camera on” warning to stay hidden.12 An Australian broadcaster reproduced the attack live, quietly pulling photographs from a (consenting) owner’s device.13 The researchers said the company took about ten months to respond; it later attributed real-world incidents to recycled passwords and promised a fix.12

DEF CON, 2024 · a worked example

Anatomy of a takeover: a vacuum with a camera, a microphone, and someone else’s cloud.

The way in
Weak Bluetooth and PIN design
Researchers showed popular Ecovacs models could be taken over through it.
What it switched on
The camera and the microphone
Both could be turned on from outside the home.
What it hid
No indicator light
The spoken “camera on” warning could be deleted to stay hidden.
Reproduced live
On air, on a real device
An Australian broadcaster quietly pulled photographs from a consenting owner’s vacuum.
The researchers said the company took about ten months to respond.
It later attributed real-world incidents to recycled passwords and promised a fix.
Sourced in notes 12 and 13 below.

The lesson isn’t that vacuums are sinister. It’s that a camera and a microphone on your floor, wired to someone else’s servers, is a surveillance device whether or not anyone meant it to be — and its safety depends entirely on a company you have to trust.

Inside · two more

Your doorbell and your television are watching too

These aren’t exotic hacks. They’re the default behavior — or the default-insecure design — of ordinary consumer gear, and regulators have already acted on both.

The Federal Trade Commission charged Amazon’s Ring with letting employees and contractors browse customers’ private videos and with security so weak that hackers hijacked cameras; by the FTC’s account, one employee spent months viewing thousands of recordings from women’s bedrooms and bathrooms before a colleague noticed. Ring settled for $5.8 million and was ordered to delete algorithms built from improperly viewed footage and to require multi-factor authentication.14 Ring had also built a police-facing side — a feature letting departments request residents’ doorbell video — which it discontinued in 2024 after sustained criticism.16

Televisions do it more quietly. Vizio installed “automated content recognition” on roughly 11 million sets, switched on by default, tracking what appeared on screen second by second and selling those viewing profiles — without meaningful consent. It paid $2.2 million to the FTC and New Jersey and was ordered to obtain opt-in consent going forward.15 Vizio noted the data wasn’t tied to your name; it was tied to your IP address and your household. The common thread across the vacuum, the doorbell, and the TV is that the watching is built in, not bolted on.

Enforcement already on the record

Regulators have acted on both the doorbell and the television.

RingAmazon · FTC
$5.8Msettlement
Employees and contractors browsed customers’ private videos, and security was weak enough that hackers hijacked cameras. Ordered to delete algorithms built from improperly viewed footage and to require multi-factor authentication. The police-facing video-request feature was discontinued in 2024.
VizioFTC · New Jersey
$2.2Msettlement
Automated content recognition shipped switched on by default across roughly 11 million sets, tracking what appeared on screen second by second and selling the viewing profiles. Ordered to obtain opt-in consent going forward. The data was tied not to your name but to your IP address and your household.
Sourced in notes 14, 15 and 16 below.

The thread

You bought the device. You don’t control it.

Both halves of this page share one root, and it’s a legal one as much as a technical one.

The thing recording you — on a pole or on your shelf — runs someone else’s software, on someone else’s terms. And under Section 1201 of the Digital Millennium Copyright Act, bypassing the digital locks on a device can itself be unlawful, so it is often the manufacturer, not you, who decides whether the camera can be turned off, whether the data leaves, and when the product simply stops working.17 The Copyright Office grants narrow repair exemptions every few years, but the default runs the other way — which is why the right-to-repair fight and the surveillance fight keep turning out to be the same fight.

Whether it’s a city camera you never agreed to or a vacuum you paid for, the shape is identical: you are surrounded by devices that see you, and you have the least say over them of anyone involved.

Why you cannot simply switch it off

The lock on the device is backed by copyright law.

Step one
It runs their software
The camera on the pole and the vacuum on your floor both run code the manufacturer controls.
Step two
The lock is legally protected
Under Section 1201 of the Digital Millennium Copyright Act, bypassing the digital locks on a device can itself be unlawful.
Step three
So they decide, not you
Whether the camera can be turned off, whether the data leaves, and when the product simply stops working.
The Copyright Office grants narrow repair exemptions every few years. The default runs the other way.
Which is why the right-to-repair fight and the surveillance fight keep turning out to be the same fight.
Sourced in note 17 below.

Where we come in

What you can actually do

You can’t opt out of a camera on a pole. But you can shrink your own exposure, and you can push on the parts that are decided in public — which is the whole reason this club has two sides.

Receipts

Every claim, sourced

We link primary sources wherever we can — the agencies’ own filings and reports, the researchers’ findings, and the companies’ own responses — and we state each side’s position. Where a claim is contested, we say so in the text.

Sources17 references
  1. Electronic Frontier Foundation — investigation into Flock Safety (2025): more than 12 million searches by over 3,900 agencies, searches tied to protests, Romani people, and reproductive healthcare, federal access to a state’s data, and the October 2025 plan to expand gunshot microphones to detect “human distress.” eff.org
  2. Oaklandside — reporting on the Oakland Police Department’s annual report: 293 readers recorded 638,747,333 plate scans in 2025 and 1,099,837 hotlist alerts, only a fraction producing leads; OPD calls the cameras “one element.” oaklandside.org
  3. Electronic Frontier Foundation — overview for neighborhoods weighing plate readers: little empirical evidence that such surveillance reduces crime. eff.org
  4. Oaklandside — explainer on Flock cameras: the Atlantic City plate-reader study’s mixed findings, reporting that Texas officers searched plate data to find an abortion patient, and cities limiting or ending their contracts. oaklandside.org
  5. Flock Safety — the company’s response to the compiled security research: it registered the vulnerabilities with the national CVE database and says they do not undermine its customers’ public-safety objectives. flocksafety.com
  6. WABE — coverage of Benn Jordan, the Cobb County musician and researcher who, working with others, documented Flock camera vulnerabilities through hands-on testing. wabe.org
  7. Engadget — reporting that roughly 70 Flock cameras were exposed to the open internet and viewable without a password, including cameras designed to track people rather than plates. engadget.com
  8. Flock Safety — the company’s own analysis, claiming its technology helps solve roughly 700,000 crimes a year, about 10% of reported crime nationwide. flocksafety.com
  9. American Civil Liberties Union — roundup of more than a dozen wrongful arrests from face-recognition matches, including Robert Williams, Porcha Woodruff, and Randal Reid, and the photo-lineup problem that compounds the error. aclu.org
  10. Innocence Project — on face-recognition misidentifications: at least seven confirmed cases, six involving Black people, and evidence the software is significantly less accurate for people with darker skin. innocenceproject.org
  11. The Colorado Sun — reporting that Flock cameras helped arrest a suspect in the killings of three women, and that an Oakland NAACP chapter argues automated reads can reduce biased, discretionary stops. coloradosun.com
  12. TechCrunch — on DEF CON 32 research by Dennis Giese and Braelynn Luedtke: Ecovacs robot vacuums could be taken over via Bluetooth to switch on the camera and microphone with no indicator, the warning sound silenced, and the company slow to respond. techcrunch.com
  13. ABC News (Australia) — a live demonstration in which a researcher silently captured photographs from a consenting owner’s Ecovacs device. abc.net.au
  14. Federal Trade Commission — charges that Ring allowed employees, contractors, and hackers to access customers’ private videos — including an employee who viewed thousands of recordings of women’s bedrooms and bathrooms — settled for $5.8 million with deletion and security requirements. ftc.gov
  15. Federal Trade Commission — Vizio’s $2.2 million settlement with the FTC and New Jersey over automated content recognition installed on about 11 million televisions, tracking viewing second by second and selling viewing profiles without consent. ftc.gov
  16. Electronic Frontier Foundation — analysis of the Ring settlement and the civil-liberties concern over police access to doorbell footage without a warrant. eff.org
  17. Electronic Frontier Foundation — how Section 1201 of the DMCA makes bypassing a device’s digital locks unlawful absent a Copyright Office exemption, letting manufacturers restrict repair and modification of products you own. eff.org

Get involved

It’s free, open to everyone at Pitt, and joining takes about a minute.

No dues, no experience needed. Come to a meeting, or leave your name and we’ll tell you when the next one is.