Boston's mayor announced in September 2026 that the city had cut ties with Flock Safety, the license-plate-reading camera vendor behind its automated surveillance network. The trigger wasn't a hack β it was a configuration setting that left Boston's plate-reader data searchable by police departments across the country, for purposes the city never approved.
What actually happened
Flock's cameras photograph every car that passes a fixed point and log the plate, timestamp, and location. Departments that buy into the network can share that data with other agencies, and by default, Boston's data was shared far more widely than city officials realized. Once the configuration was flagged, Flock closed the hole. But there was no audit trail showing who had already run searches against Boston's plates, and the underlying records had already rolled off after their standard 30-day retention window. Boston residents didn't learn any of this until roughly seventeen months after the exposure happened.
Automated plate readers are attractive to departments precisely because they're cheap and passive: no officer has to run a plate manually, the system just logs everything and lets anyone with access search it later. That convenience is also the entire privacy problem β the system doesn't know the difference between "investigating a stolen vehicle" and "checking where an ex-partner parks."
Cancelling the vendor didn't turn the cameras off
This is the part that got buried under the "city bans surveillance cameras" headline: the Boston Police Department had already installed 75 license-plate cameras from other vendors, Motorola and Axon, before the Flock cancellation was even announced. The plate reading didn't stop. The logo on the camera changed.
Public records showed around 11,000 searches against the plate database in five months. About half of them carried no case number at all, meaning there's no record of what investigation, if any, justified the lookup.
The real risk was never the vendor
Swapping Flock for Motorola doesn't fix the actual failure mode: a plate-reader network is only as trustworthy as every individual officer who has a login. Nationally, hundreds of officers have been formally accused of running plate or database searches for personal reasons β checking on an ex, a neighbor, a family member β with no case attached. A vendor swap doesn't touch that. Neither does a press release announcing the old contract is gone.
Here's the 60-second version:
What to actually watch for
If your city announces it's "ending" a surveillance camera contract, the headline question isn't which vendor got fired. It's:
- Did the hardware actually come down, or just get relabeled under a new vendor?
- Is there an audit log tied to every search, with a mandatory case number?
- How long is data retained, and who can still pull it before it expires?
- Is oversight independent of the department running the cameras?
Boston's story is a clean case study because the paper trail is public: a Flock misconfiguration, a fix with no accountability for prior access, a 30-day retention window that erased the evidence before anyone could audit it, and a quiet buildout of a replacement network using different hardware from the same playbook. None of the incentives changed. Only the branding did.
If you want to go deeper, UFD Tech's coverage is what originally surfaced the Boston details referenced above: https://www.youtube.com/watch?v=BXDzO9YWGbI. Worth checking next: how your own city handles public-records requests for plate-reader search logs. Some departments publish them by default; most don't, and that gap is where accountability quietly dies.
Top comments (0)