28 ms·
> weren’t authorized this is easily solved with current technology, if they had an incentive to do so. besides firing folks that get caught, flock themselves
by jiveturkey 2mo ago
> weren’t authorized
this is easily solved with current technology, if they had an incentive to do so.
besides firing folks that get caught, flock themselves should be brought to court.
- akerl_ 2mo agoThis feels like a weird comment on an article about how they monitored usage, identified misuse, and terminated the people involved. There's surely plenty of entities that need better controls around usage of technology / records / etc, but this is an example of somebody having an incentive and then following through.
- paimapi 2mo agoit's also possible that we're only seeing a few select departments fire their officers. there are no laws around this as far as I'm aware so enforcement is purely departmental policy. how many sheriff's offices and police departments do these audits and how many of them act on abuses? you should need a warrant to monitor the products of mass surveillance and it should be as narrowly targeted towards a suspect as possible. or just not have any of the mass CCTV placements everywhere in the first place
- akerl_ 2mo agoI think we may be agreeing? I'm in favor of pushing for police departments (and really any governmental body with access to any kind of data) to have regulations around access to that data, access controls to restrict illegitimate access, and monitoring to detect improper access by people who do have legitimate access but don't follow the proper regulations. I think you're correct that we don't tend to see the instances where improper usage occurs, tautologically because those entities aren't doing their homework on the above.
- paimapi 2mo agoI think the point we disagree on is the idea that accountability by a singular department is an indication that it's sufficient for vendor to avoid regulatory action. in terms of privacy protections, the strategy should be defense in depth. I think about the audits that happen in health tech for eg on the software side, both at the request of regulatory agencies and their clients any platform that enables people to be stalked, harassed, tracked, and so on should face the same level of scrutiny in the form of auditing and open access to internal policies around data sharing
- akerl_ 2mo agoYou're correct that we disagree on that point. Flock is providing a tool; if we think the tool can be used in problematic ways, we ought to regulate users of the tool (in this case, government entities). This has the added benefit that the burdens on the government around their treatment of citizens have a higher bar for transparency and conduct than we place on private entities.
- paimapi 2mo ago"it's not the gun, it's the person that holds it" is not a philosophy that's tracked with me given the probabilistic, population-wide outcomes. the same applies here - tools should build in strict data and privacy protections as part of their UX. you lower the probability of abuse wherever you can because you know a bad actor will find a way, regardless, but the point is to add enough friction that even the worst of the bad actors has a difficult time getting what they want
- lux-lux-lux 2mo agoSystems should be built so abuse isn’t allowed in the first place, in addition to monitoring for compliance.
- akerl_ 2mo agoThere always ends up being a real world to digital interface and it always has the potential for abuse, and thus always requires some level of monitoring and validation. The department in this article appears to be doing just that: > Every search run through the Flock Safety platform is automatically logged — who ran it, when, and the reason they gave for doing it. SPD said they also have other safeguards in place, including mandatory training, role-based access controls and supervisory oversight.
- garbagewoman 2mo agoits good PR for these systems that they are very keen to roll out, i would say theres a vested interest in stories like these from the exact agencies deploying them
- akerl_ 2mo agoI'm getting https://xkcd.com/810/ https://xkcd.com/810/ vibes. If government entities get good PR for rolling out strong policies, practices, and tooling for the data they have, and that makes more of them very keen to do so... mission accomplished?
- garbagewoman 2mo agoThats a very idealistic and optimistic outlook
- akerl_ 2mo agoIs it? Cards on the table, I am an optimist. But this feels pretty realistic: it's basically a corollary to the idea that public outrage about bad policies, bad practices, or bad tooling is problematic for these government entities. They want to avoid it. There's plenty of examples of this, even honing to just the US. Increasingly there's even examples of this specifically in the US, for police departments, for usage of Flock.
- morkalork 2mo agoAh but you see flock doesn't own the data so they're not responsible for misuse of it and other such legal deflections.