License plate reader searches should require a warrant
335 points - today at 2:43 PM
SourceComments
This middle ground that municipalities try to carve out where itâs fully open to police without a warrant but not subject to FOIL laws doesnât appear tenable for much longer.
Thereâs been too many cases of police officers stalking exes, poking around the data for fun and such so itâs clear police cannot be trusted with the data without better court oversight.
Itâs certainly a very powerful investigative tool, but needs solid 4th amendment protections. The Supreme Courtâs recent ruling on geofence searches of cell phone records is a good indication on where the Supreme Courtâs head is at on this sort of thing, where they said no you canât just do blanket data dumps like that without a warrant.
The right of the people to be secure in their persons, houses, papers, and effects...
Who is "their" here? In terms of property rights it's the people who own those digital "papers". The individuals who that data is about do no maintain or control that data, and could not destroy it, meaning they do not functionally have property rights over it. If I write in my notebook that you have blonde hair, the notebook is still my property. There isn't anything I could write about you in it that would make it yours (other than maybe "I hereby give this notebook to Joe Bloe").Attempts to interpret the Constitution otherwise are, IMHO, attempts at good policy, but unstable as law. So we should fix it either by giving people property rights to that data (so that they can destroy or change it without permission) or to explicitly require warrants for access to PII owned by third parties.
A warrant requirement is not a reasonable bandaid to consider allowing mass spying. There should be no mass spying by default.
A warrant requirement makes sense for something like the locations of customers on cellular networks, because, although it should be improved, it's been built into the tech.
When you make the optional choice to create mass spying, safeguards do not make it acceptable.
We lost a lot of strong privacy rights we had with landlines when we shifted to cell phones.
We're actually slowly creeping into pre-crime territory. You could have AI searching for possible pre-crime candidates based on unknown identity in the area, disparate pattern to usually movements, etc.
It seems that would easily impede a lot of abuse and itâs straightforward to believe that historical data is rarely so urgent as to not require a warrant.
A matter of defining historical as a sufficiently old enough thing but that seems feasible.
In my conversations with law enforcement (mostly at management level, chiefs of police), all of them have had reasonable-sounding objections to a warrant requirement for a search, but zero of them have been able to come up with a reason why a case-or-CAD ID requirement isn't workable. Generally, they argue that in practice obtaining a warrant can be too onerous in time sensitive situations, and can be harder to obtain than the public realizes. Two popular examples are in kidnappings (time sensitive) and missing persons (difficult to obtain).
A case number or CAD ID however simply requires that the details of either a public call for service or an active investigation are associated with the historical search. It closes the door on officers' hobby searching.
Andrew's blog post does note the problems with oversight, which also match my experience, so this isn't a perfect fix. But it will go further in conversations with law enforcement for people that are trying to thread the needle on making "safe" mass surveillance.
(I am personally opposed to mass surveillance in all its forms, but arguing only from that position pretty much immediately excludes me from policy discussions.)
> I think cameras in all public spaces are going to happen. Imagine Ring comes out with a nicer camera system for homeowners....
Indiscriminately filming people in public places is illegal some places, e.g. Germany. Allowing the creation of large networks of cameras surveilling public places is a choice.
Access control (warrant) doesn't prevent a breach, and the system is not architected in a way to prevent internal abuse. The best way to prevent the abuse of data is to not collect or store it at all.
Why should it be possible for my bits be scooped up and sold for profit against my will.
Is it legal for a private entity to do the same with their owned space (like a plaza or mall or office tower)?
Focusing on license-plate-readers seems like car-brain is causing the author to miss the forest for the trees.
I know it's unpopular but I went from not supporting these sorts of systems to embracing them after seeing the positive effects in China.
For crimes that depend on anonymity, theft, assault, hit-and-runs, vandalism, illegal parking, etc., surveillance changes the calculation because the offender expects a higher or even a near certain chance of being identified/caught in China. I think this is a good thing. I also see no issue with someone breaking the law and receiving a ticket almost immediately.
With all systems, it comes down to the design. What sort of oversight is there, how long is footage stored, can it be used for specific crimes or expanded later, and are there mechanisms to correct false identification.
Done right, these systems work well. I would be happy to live in a society where street crime is rare enough that I can leave personal property anywhere, like a bike, without constantly worrying about theft. I think many fears about these systems come from dystopian science fiction and assume the worst possible implementation, rather than recognizing that technology can be designed with strong safeguards.
1) remove the hazard
2) replace the hazard with something less hazardous
3) isolate the hazard (guards, cages etc)
4) administrative controls (procedures, training, warning, etc)
5) PPE
Implementing some kind of judicial review for these panopticons is something like 4) in the hierarchy. It would be a good thing to have, but we can go far further. Why do we need this shit? Oh what so someoneâs car doesnât get stolen a few times per year? I think my values are in line with the founding fathers and most Americans when I say I would gladly give up a little bit of safety to not have a spy camera trained on me 24/7.
I would like more removal and less procedural controls. The cops cannot abuse a system that does not exist.
I wonder if people who feel this way will feel safer? In this scenario, you have a Ring camera system observing your entire property. Do you feel safer if someone comes onto your property and triggers an alarm? What if it turns out it's just a kid coming over to grab a stray frisbee? What if your neighbor noticed something needed a quick fix (say you left a can of paint open or something similarly benign) and wanted help in a neighborly way without first checking to see if you were home?
I guess we just take for granted that we live in a low-trust society. But we take that for granted at our peril, because the fear of a low-trust society is actively being exploited by people who want to sell individuals, businesses and municipalities the means to further erode that trust.
The accused has comparatively no rights when an bureaucrat is shaking them down and the accused is often a business rather than an individual it's easy to have sympathy for. Flock could've run their racket for many years, got much praise from the useful idiots, really gotten their system integrated and entrenched, if they'd have chosen that route.
Their mistake was believing in their own bullshit. They thought they could make it cheaper to solve crimes (at great cost to everyone's rights of course, but they thought this was acceptable) and make things better (or at least their definition of it). If only they had been slightly scummier and instead set out to help municipalities collect civil fines they probably could have gotten away without scrutiny.
There are civilian enterprise uses of ALPR. Where do they fall in this? I don't even mean for mass data collection or even for parking enforcement. I'm thinking of like various car washes where they offer monthly memberships and their car wash portal system has plate recognition to tie your membership to your car. Or other enterprise access control applications where the ALPR pops the gates open instead of RFID tags.