Hacker News new | ask | show | jobs
by chaps 15 days ago
No need for snark; I'm genuinely interested in your position. From my re-read and re-read, you've provided a conclusory statement without actually explaining the details.

Is your definition of "stupid" anything that contradicts 50 years of case law? That seems.... tautologically limp.

1 comments

I’m saying it’s stupid to equate viewing = searching for multiple reasons. 1) A lay understanding of a search would require way more than just seeing and recording the license plate of a car on a public roadway. 2) Courts have extensively and repeatedly upheld the idea that cops can examine your car, your house, your trash can, your curtilage, and more without it constituting a search. To backpedal and now claim being observed driving on a public roadway is a search creates a huge contradiction in the law that will need to be resolved by either kneecapping basic police investigation or rightfully reversing the idea that you can’t be observed on a roadway displaying a government issued license plate without a warrant.

Do you mind providing your position? Do you think being observed on a public roadway constitutes a search or seizure in the context of the 4th amendment?

My position is that no amount of policy will ever make these tools safe, fullstop. I've been an investigative journalist doing research into the use of technology by police and prosecutors and the shit I've personally seen is beyond shameful. The modes of failure for these systems are such that it's inevitable that they'll be abused and even when abuses don't happen, accidents do. And also FWIW, I've been a sysadmin at some pretty large companies, have seen how the meat is made, and I have a deeply grim understanding of how systems are secured.

Some example: Chicago Police Department accidentally sent me the ALPR XML data from the state's system (LEADS). The data included about a thousand social security numbers, many credit cards, the fingerprint hashes. This happened during FOIA litigation and when we raised it to them, instead of freaking out, they asked us if wanted them to actually redact. We said yes, they came back later and the XMLs still had many SSNs and credit card numbers. Third time was better, but it's still awful. Thousands of pages.

Another example: City of Chicago has given me the license plate records for millions of vehicles through FOIA. You can read about it at the end here: https://mchap.io/losing-a-5yr-long-illinois-foia-lawsuit-for...

Another example: Cook County Sheriff's Office's electronic monitoring program was using a 20 year old webserver that was exposed to the internet, leading to this: https://www.vice.com/en/article/contractor-exposed-the-movem...

Another example: City of Seattle accidentally sent me 30 million emails (including police): https://mchap.io/that-time-the-city-of-seattle-accidentally-...

The town I grew up in was a target of Bovino's ICE. A FOIA request for the usage of Flock in that town returned back the longest FOIA denial I've ever received, and I've done thousands, including over a dozen lawsuits. The friends that I graduated with, who think of this country as their home are being targeted. It's hard to express the grief of that. https://www.muckrock.com/foi/waukegan-11153/flock-safety-alp...

Another example: Recently I even found an S3 bucket used by police to share photos of people across state lines. Just... on the internet. Facial recognition, flock, etc.

I think you're hyper-focusing on the 4A public space stuff honestly. The 4A issue that I specifically research is about the extent of exculpatory information given to defense attorneys during criminal prosecution. Of the 150 arrests done by Chicago Police that I found in Flock audit lots, only one arrest report actually mentioned Flock. People have a 4th amendment right to have access to the exculpatory information about their arrest in order to make a proper defense.

This is all just stuff that I've found in my research and I feel like I've barely scratched the surface.