- Messages
- 803
Not at all. I'm worried about Flock having access to all this data. I'm worried that employees inside Flock can abuse it. That Flock's customers (for example police agencies) haven't learned yet how to prevent abuse. I'm wondering whether a large aggregation of free and public data rises to the level where accessing it constitutes a "search" in the sense of the 4th amendment.Are you of the mindset that there's nothing to see here?
A lot of this can be solved by learning the ropes. For example, if you work in the big computer and software companies of Silicon Valley, in particular the ones that deal with PII and medical HIPAA data, or with any government-restricted data (export controlled, ITAR, classified), the first thing that happens is that you go to a training class, and get given a big policy document about "do and don't". For example, the average Microsoft/Apple/Google/Facebook/IBM/Northrop/... employee knows exactly that individual customers (Bob User) is NOT identifiable to them, and that Bob's identity has been carefully transcoded into a 128-bit opaque ID. They might be able to see that user ID 0x1234ABCD stored a file that's 987,654 bytes long yesterday at 11am, but they are not allowed to dermine what Bob's ID is, nor can they find out who 0x1234ABCD is. If they try to use the user-to-ID database, and audit record is created, and 5 minutes later their phone rings: Why did you look up who Bob User is? They also can not read the file mentioned, because it is encrypted with Bob's private key. If they look at the database with the encryption keys, the phone will ring again. Similarly with medical data: It is anonymized during processing and storage by using opaque IDs, and by splitting the data. I've seen corporate security (we used to call them "red shirts", but their shirts are not actually red, too Star Trek) walk up to an engineers desk and tell them "please follow us to the conference room NOW, someone from audit has some questions they'd like to ask". In the case I know, the engineer came back half hour later, visibly angry, and complaining that the idiots from audit don't understand anything and wasted his time once again.
There are people who have permission to do just about anything to data in such corporations. They have background checks done on them, just like the military and the intelligence agencies do. Often, these potentially sensitive operations require two people in the room, and can only be done in special conference rooms with frosted glass windows, using special network outlets and wired connection. We used to call those "panic rooms". Example: "We just got a subpoena, and need to look up all pictures Bob User received from underage girls in the last 24 hours, and make a list of the user ID's of those girls, and then tie it back to the cell phone location of the girls". And yes, working in big computer companies, you know people who've had to look at some VERY disgusting pictures, and after coming out of the panic room they go do see some counseling to talk about what happened, and take the rest of the day off.
And occasionally you do hear stories where people were fired, walked out of the building, and referred to law enforcement, because they broke the rules and did things like spy on their ex-partners. That tends to be rare, and I've never seen it happen to anyone I know, nor to my (extended) department.
So in my opinion, I would trust the big established companies to handle this kind of ultra-sensitive data, and mostly be responsible about (with rare lapses). The question is: Do companies like Flock have that culture? Do they know how to write policy manuals, train employees, check that the policies are being followed, and have alarm mechanisms? Or are they "fake it till you make it" and "move fast and break things" startups, with a culture of "I don't care, I'm only here until the IPO"? I don't know.
And that's just Flock ... where the company itself holds the data (all the license plate / face / body reading), and the data is its most important asset.
Palantir is yet a different case. Palantir is not so much a data company, more a software and services company. They sell software and services to government agencies, but they don't usually have copies of the data. Palantir doesn't so much know that YOU SPECIFICALLY drove your beige Camry to the gun store yesterday; they sell the program to the ATF and CA-DoJ that links Flock data with DROS/NICS data, and the program runs on some government agencies computer (or in a Palatir data center under the control of government people). Palantir is less in the business of doing evil things themselves, and more in the business of enabling other to do evil things (and I think the company and its top executes are inherently evil).
Another thing which makes it complicated: Often, large government organizations outsource their data processing completely to contractors. For example, all of the civilian weather-related data processing in the US is outsourced to an unnamed vendor (you'd recognize the company name), and the CTO of the National Weather Service has both a government badge and a company badge. Some of the NWS's data centers are in vendor buildings, with every single staff member being vendor employees. Another example: I know that Northrop used to run one of the big data centers for a secretive organization in Colorado, loosely associated with the Space force; a friend of mine quit his job at my company to go work for them. But: Those employees have nothing to do with their vendor. It's not like other Northrop employees have access to all the pictures or signals taken by these space force satellites; it's just that the staffers (sys admins, now known as SREs) in the Colorado building happen to get their paychecks from Northrop. Again, I trust companies such as Lockheed, Raytheon or Northrop to know how to build firewalls between systems and around people. They've been doing that for many decades, and they have only made very few messes in the process.
Look at it this way: There is something you should worry about just as much, which is nukes. Those are built and managed by ... private companies. Du Pont used to run Savannah River; Pantex (which assembles the warheads) first operated by Procter and Gamble (yes, the soap company!) and now by Fluor, and so on. They have had a few scandals (Chinese spies at Los Alamos, fatal explosions at Pantex, tanks full of unknown radioactive gunk at Hanford), but for the most part, they're run well. And have neither exploded nor given ALL their secrets to the competition.
But now the worrisome thing is that the industry is moving rapidly, and new players are coming in. For example "AI data centers in space to process satellite intelligence on the fly". Or Flock as a terrestrial example. If that's done by a startup that's only been in business for 3 months, and is funded by a half-crazy person who has good connections somewhere in Washington and on Sand Hill road, can you trust them? If you can't trust them, why are you hiring then? Do we need tighter controls on them?
And the same argument goes for the police and intelligence agencies themselves. It used to be that a police detective needed to spend hours or days to find out where a car with a certain license plate had gone. Nobody in that job had the time to go spy on their ex-partner. And if they tried, the desk sergeant would notice, and drag them in front of IA. Today, it takes 30 seconds on the Flock website. Suddenly 100 crooked cops have been caught spying on their exes. That should not come as a surprise. The failure here is that the lieutenants at these agencies should have written policy manuals, put procedures in place, and run audits and checked logs. But the lieutenants are either stupid, or overworked, or naive. I think the last two are more likely explanations.