Hacker Newsnew | past | comments | ask | show | jobs | submit | harporoeder's commentslogin

There is not generally an expectation of privacy in public. Things in public can be recorded without consent. Filming a car on a street and giving that video to the government is not the same as me giving private information to a third party, and then them giving it to the government such as Carpenter v United states covers.

Edit: Note that this is not an endorsement, rather stating that recent supreme court cases may not be applicable.


Private citizens filming in public and police forces setting up arrays of surveillance cameras in public somehow don’t seem equivalent. I’m not a lawyer so I can’t properly articulate what the legal difference is. And if there isn’t one then the law needs change. Clearly the majority of citizens agree with me.

Is it legal for US citizens to all put cameras on their cars and set up a network where we can all see where all police are at any given time?

Seems like a good idea at this point.


> Private citizens filming in public and police forces setting up arrays of surveillance cameras in public somehow don’t seem equivalent.

The reason these strategies (for the same goal) don't seem equivalent is due to the nature of oversight. Flock as a centralized private company governed by a procedural system, can be corrupted and abused more easily than a distributed network. Flock's systems have already been abused and will continue to be.

Re Title: Flock doesn't "want" anything in particular, other than to sell more contracts and make more money.


The quickest way to get dragnet surveillance banned would be for citizens to collaborate and create a massive publicly-available surveillance network.

It's legal to film publically - what's not necessarily legal is what you then do with that.

There are already precedents - for example it's legal to film ICE agents in public spaces, it's not necessarily legal to use information to dox if that can be construed as harassment.

Even if you crowd sourced the identification of somebody involved in a potentially criminal act, you can only share that with the police and not the wider public.

The law is asymmetric here because the police have powers reserved for themselves to stop vigilantism.

Perhaps an interesting angle here would be if you can make the case that companies like flock are involved in harressment themselves...


It's legal for ICE to kill you in the street, lie about what you were doing, and nothing will happen to them.

> it's not necessarily legal to use information to dox if that can be construed as harassment.

This is an incorrect understanding of the issue, these individuals are protected using a unique and unusual statute. In a mass broadcast scenario, without identifying their profession in context, there's arguably no crime here. There's certainly no crime to broadcast that you've seen their license plates with no association with their names (the statute doesn't cover that.)

> Even if you crowd sourced the identification of somebody involved in a potentially criminal act, you can only share that with the police and not the wider public.

What are you talking about? This is most certainly legally false in the United States. If you are incorrect about someone you might be found against for libel, but there's no crime here. This is basic First Amendment activity. Have you never watched the news or read a newspaper? Allegations are part and parcel.

These are also entirely the wrong analogies. Both of these are highly individualized scenarios that are not akin to Flock. "Public Flock" is more like a public traffic cam that anyone can view, and these already exist without issue.


I'm trying to distinguish the collection of information from the use. Collection is legal - however there is no point to collecting it if you can't actually use it for anything.

For example:

https://www.pbs.org/newshour/nation/federal-prosecutors-char...

or https://www.justice.gov/usao-cdca/pr/santa-monica-man-pleads...


So if we all collect information and don't know who uses it, and the police can't find who uses it, nobody gets charged.

I'm well aware of these cases (and have commented about the specific statute in question in the past here.) The originally-purported analogy of a "public Flock" that you can "actually use" is completely different than what the statute protects. "Hey! Look! Here's an ICE agent's home address" is a lot different than "here's a list of vehicles who traveled down this street on a given date and time."

The statute in question is 18 USC § 119: https://www.law.cornell.edu/uscode/text/18/119

To preface: this statute is very arguably prior restraint and unconstitutional, which is likely why you only see those cases (non-affluent, non-connected defendants.) Furthermore, you'll notice that it requires "intent to threaten, intimidate, or incite the commission of a crime of violence."

I hate to get specific into this one very questionable statute, but no general/broad restrictions exist with regards to disseminating the video data or license plate information contained within. License plate data doesn't fall into the statute's definition of "restricted personal information," and the operator of a hypothetical service that doesn't single out these "protected" individuals amongst the rest of the population cannot be possibly construed as having malicious intent. This is an extremely unusual statute, few others like it exist.

A "public Flock" would let any interested party query the entire database of observed license plates. Collection isn't individualized to any one person, use and intent resides with the individual consuming the service.


The original posters premise was the way to make government dragnet surveillance banned was to do a public one. In general it's a good principle however I'm not sure in this case.

I can see how a public flock, which is just a queryable database, would be ok under the current rules. But would it make the government want to regulate? They could just continue to go after data use where legal asymmetry already exists.

You could frame almost any use as some sort of stalking/harassment.

Even in this case if they shut it down, government carve outs would apply.


Yes. Once the application of force happens outside the state's monopoly, they'll shut that shit down so fast.

I loathe surveillance networks. As much as I loathe them, I'm sadly forced to concede that probably citizens setting up a trivially join-able, anonymous, open source surveillance network is probably the only way to get the powerful to think about what they're doing.

Every door man, every hotel employee, every uber driver, every concert-goer, every grocery shopper, every student, and on and on and on. Anonymously streaming their encrypted feeds. Have them turn their cameras onto the street. Especially, say, in front of hotels or at certain restaurants and resorts. Ohhh, and at convention centers as well. Just to show it can pick out subjects at busy places and track them around any city reliably.

Naturally, we'd need some sample facial recognition queries just to show how to use the system. We could start with, say, public figures like Representatives, and Senators? And just to prove it works for less famous people, maybe we could have some example names of regular, everyday employees. Like employees at, I don't know?? Palantir, Flock and Clearview maybe? Just to demonstrate the value and effectiveness of public surveillance networks.


I guess I'm more cynical at this point. This isn't the 1970s when a congressman freaked out that his video rental history might leak and passed a law making them private for everyone as cover. They've evolved beyond that. They'll pass a law banning it for individuals but leaving a loophole for themselves. Like how Chat Control always contains a provision so that officials messages aren't a part of the dragnet.

Good luck getting permits to install your citizen flock in public areas.

Enough private businesses abut major thoroughfares that this is a non-issue.

... of politicians. Because they are the ones who could write the laws to ban privacy invasive solutions.

> Is it legal for US citizens to all put cameras on their cars and set up a network where we can all see where all police are at any given time?

Sure. There's absolutely nothing illegal about monitoring the location and activity of police (unless you broke some other law to do so, like hacking).

Hell, most of them will simply tell you where they are and what they're doing, as they tend to broadcast over unencrypted radio (which is also not illegal to listen to).


> There's absolutely nothing illegal about monitoring the location and activity of police

In theory, sure. In practice? Good luck.

https://www.forbes.com/sites/siladityaray/2025/10/03/apple-t...



Another area that's also existed for quite a while is the crowd-sourcing of the positions of mobile speed traps.

Though bizarrely in the UK that's legal if you do it via Waze, not if you do it via whatsapp.


Yes, it's different. It's a legal doctrine called mosaic theory.

https://share.google/f10FzHcf2jPqSzTRM


The language doesn't really cover things correctly.

You don't expect privacy in public in the sense that you might bump into other people that know who you are.

That doesn't automatically mean that you expect walking into a public area means a system will start investigating you and seeing if you match with crimes.

Assuming everyone in public is a suspect and continually investigating them, is a big change in how society works.


>Assuming everyone in public is a suspect and continually investigating them, is a big change in how society works.

Well that's not exactly how it would work.

Everyone is tracked, but only certain people are watched. That added to the fact that any nation with a sufficiently complex legal system has no law abiding residents. You've always broken some law, somewhere.

So it would be more like:

>[Pick any person from] everyone in public [and the system has the capacity to list the reasons why that person] is a [criminal]


> Everyone is tracked, but only certain people are watched.

The "only certain people are watched" hinges on pinky swears, winks, and nods. IMO it's a distinction without a difference.


These systems aren't perfect recognition oracles - there are lots of errors, especially as you scale up the technology. At the end of the day, it's a probabilistic identification correlated to a stream with a mix of of reported or suspected crimes. Your framing completely misses the reality. I'd argue that the OP's language is a much better fit.

It's the same with all of these issues; the frog always gets boiled. In the same way the people who drafted the Constitution/Bill of Rights couldn't have imagined AR-15s, they could never have imagined a (practical) surveillance network capable of tracking people (historically and in real-time) in the way Flock, Axon and these other shady fucks do.

>There is not generally an expectation of privacy in public.

And that's the problem, because if there isn't an expectation of privacy, and we record everything that's "in public", we land in a dystopic hellscape.

The problem is really that "privacy" vs. "public" isn't a binary choice. Yes, I expect people to see me in public if they happen to walk by. That's quite different from every movement being recorded and made searchable. Most privacy laws don't really account for that being possible.


Likewise being recorded on a cctv camera which sits on a vhs for a few weeks and then is consulted when a crime has occurred is very different to being recorded on a camera and being immediately processed, analysed, and information kept forever, including “person X arrived at time Y accompanied by person Z”

It’s a question of scale and ability.


Rehnquist anticipated but unfortunately did not prevent the abuse of the third party doctrine back in 1983.

“Respondent does not actually quarrel with this analysis, though he expresses the generalized view that the result of the holding sought by the government would be that "twenty-four hour surveillance of any citizen of this country will be possible, without judicial knowledge or supervision." But the fact is that the "reality hardly suggests abuse," If such dragnet-type law enforcement practices as respondent envisions should eventually occur, there will be time enough then to determine whether different constitutional principles may be applicable.” — United States v. Knotts, 460 U.S. 276, 284 (1983)

https://www.law.cornell.edu/supremecourt/text/460/276


Flock goes far beyond that, they allow the government to retroactively string together a person's history of movement. Prior cases establish that continuous and retrospective tracking like that violates a reasonable expectation of privacy and requires a warrant.

"

The third-party doctrine is a United States legal doctrine that holds that people who voluntarily give information to third parties, such as banks and phone companies, generally have "no reasonable expectation of privacy" in that information. This precedent, established in Supreme Court cases in the 1970s, allows the U.S. government to obtain information from third parties without a legal warrant and without otherwise complying with the Fourth Amendment prohibition against search and seizure without probable cause and a judicial search warrant. "

https://en.wikipedia.org/wiki/Third-party_doctrine


It's like allowing police departments to hire a hitman to avoid the Fifth Amendment.

I'm not voluntarily sharing my license plate number. I'm legally required to display it.

They are relevant and courts have considered the whole of a persons movements standard in terms of whether querying ALPR data constitutes a search, https://andrewpwheeler.com/2026/08/12/license-plate-reader-s...

Under current case law (Carpenter and recently affirmed in Chatrie) it will definitely be a search, IMO it is just when the sensors become dense enough according to the court (absent states do not make regulation themselves to require a warrant for historical data).


> There is not generally an expectation of privacy in public. Things in public can be recorded without consent

This is _not_ universal. Many jurisdictions take a different view on this.


Yes, there is an expectation in the history of free society that the government is not proactively observing every person on every block, asking for ID, and following them down the streets, then documenting that and correlating it with other people's activities and making it accessible to law enforcement personnel without a warrant across the country.

I retch when people say there is no expectation of privacy in public as some naive defense of the panopticon.


> There is not generally an expectation of privacy in public.

Which is entirely different from an expectation of a generalized systematic loss of practical privacy in public.

They are not even close to the same thing.

The willingness to kneel to others baffles me. Loss of practical privacy is loss of power - to somebody(s). It may not seem so for one person. But when it is true for everyone, the system will adapt to using that power.

Throw in AI and data integration. This is clearly a B.A.D. idea.


All that means is that the ends (and not the means) are the determining factor.

A private company can have plenty of legitimate reasons to film in public spaces, and to incidentally film people.

Flock's ends are to explicitly track people, and to use that data to accuse them of criminal activity. Those are the ends that the 4th amendment is written to explicit protect us from that, and not exclusively from governments, either.

> The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.


> There is not generally an expectation of privacy in public.

Surely we can agree the point of this technology is to change the level of privacy one should reasonably expect in public?


Prompting a system to give a history of a person’s movements (even if they’re movements “in public”) is not something that has any historical analogy. The law has slapped down the “it’s in public” argument in cases like this, see eg Baltimore’s ubiquitous aerial surveillance (they put a wide-angle lense on a surveillance plane and recorded everything, so they could rewind and search anyone’s locations.)

I don't think that's actually true. Follow someone around reading their phone over their shoulder and see how people react.

In human terms, frequency, impact, and scale matter. If my little dog puts a few ounces of pee in some random person's front yard, it's seen as a micro-infraction at best. Vs. Flock's ideal is more like a factory farm just up the hill, with ever-leaking urine retention ponds.

Cool we should maybe change those laws then, these definitions of privacy came about in a world where there weren't cameras on everyones face and front porch.

The US government, the 4th reich, cannot be trusted with these tools, especially their law enforcement.


Without any real privacy laws, Americans should not have the expectation of privacy in private spaces either. Your search history, real time location, biometric data, consumer habits etc. are all for sale to anyone who wants it.

Isn't there a difference between getting picked up on someones Tik Tok "broadcast" and a private/public surveillance operation?

This is essentially what containers are. Bubblewrap / Docker / Podman. I think the primary issue is very few applications on Desktop systems are actually designed with sandboxing in mind unlike say something on a phone.


I'm not terrible familiar with Linux container systems, cgroups and all that, but I have been down the rabbit-hole with FreeBSD's jails, and I definitely wouldn't call them a capabilities system. You can lock down the environment quite a bit, and limit or even virtualize the network stack, but you can't say, "Here process, have your standard IO streams and nothing more. Go forth and compute." The process isn't blind to it's environment. You're still in the same basic UNIX user security model. It's really somewhere between chroot and full virtualization.


A default container seccomp profile will let you do quite a few things but you can use a different profile some json and limit to just a few system calls if you want such as doing IO on open FDs without the ability to open them. I think the runtime opens the FDs before the child process starts and are inherited.


The killer application in this case is ATAK.

https://en.wikipedia.org/wiki/Android_Team_Awareness_Kit


If anyone wants to help make MANETs better with TAK… check out opportunities on ditto.com where the team is building crdts and using them to help enable SAR. Say Turner sent you in your application if it looks interesting. Particularly the FDE role.


Is ATAK even useful to civilians? Is it trustworthy?


Yes and yes, we've used it for civilian Search & Rescue in tandem with CalTopo.


I use it for hiking, its great.


How do you use it for that?


Can design then export routes from any geospatial tool like CalTopo, AllTrails, or even WinTAK directly to your ATAK device. Then in ATAK you can use it basically as something like AllTrails on steroids, including offline map caching, route guidance, markers, tracking etc... even geotagged photos. This can be synced across multiple devices among friends using a TAK server. It can also be used for off grid communications and tracking between hikers via something like Meshtastic, which I use fairly regularly with my partner out camping well outside of cellular coverage.

ATAK is not necessarily the most intuitive UI, but it's crazy powerful for doing basically anything outdoors.


It is an offline moving map with very fancy marker etc support. Seems a good choice for a hiking app?


I have had pretty good success with steam inside docker. Things like playing counter strike have been pretty seamless. It's cool to see others doing the same. I'm waiting for wayland isolation stuff to actually be integrated into everything (security contexts etc). Even with all this isolation passing in an X socket totally breaks any security guarantees against anything actually malicious. For other apps I can do the dummy X server trick (nxagent etc), however for gaming that is really not an option with the performance requirements.


I use sway and I think it supports security-context-v1, though I haven't tried it. That said, my current setup is just to run cage + xwayland inside the container which gives decent enough sandboxing AFAIK. (I used to use Xephyr but the cage approach gives me dynamically resizable windows). At the very least the host clipboard is not shared with the sandboxed process, which is the primary thing I'm concerned about.


With dependent types you still end up having to do dynamic checking of invariants for a substantial portion of real world code to construct the value with the properties you want. Anything coming from disk or network or a database etc. In practice I feel that it is far easier to just do manual dynamic checking with the constructor hidden from other modules such as `constructEmail :: string -> Email' which uses normal value level code, a common Haskell pattern. Obviously a little less flexible for the common dependent type examples of such as appending two vectors of a specific length.


You should be parsing/validating any value coming from disk or the network


You never know when the file will just suddenly be all zeros.


While I'm not sure I would claim it is practical, playing around with eaglemode is fun. It is available in the AUR among other places

1. https://eaglemode.sourceforge.net/screenshots.html 2. https://aur.archlinux.org/packages/eaglemode


There are lots of ways to protect your system from a browser exploit via containers, another user, a vm, etc as brought up by other people responding. However protecting a browser from other applications is basically impossible unless you also sandbox everything else you are doing. Even if you run a browser in a VM some other process run as your user could just automate clicking the UI to do whatever. If you go qubes style and isolate everything from everything then it is fine.


Protecting the browser from other applications is arguably more important now than protecting applications from the browser; as the browser contains all your security information (cookies, etc) necessary to login (or be logged in) on all your important sites.

People have been hacked by malicious Minecraft mods uploading browser data to nefarious places.


Even with direct mutual references between some node type this can be represented in a lazy functional language such as Haskell pretty easily without mutation.


Interesting. I had no idea CBRS existed. Can you provide any more information about the base station and what your experience was like?


Line of site transmissions can go massively further than with even minor obstacles. While a different frequency amature radio operators easily contact the ISS on $30 5 watt handheld radios. If I recall Iridium phones are only a couple watts.


Also it's all about SNR, not absolute power. And you can infinitely decrease bandwidth to increase snr.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: