This is pure laziness aka “reduced time to market” on the part of Flock.
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
Any breach of security on a system like this is a big flashing red-alert to me.
If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.
Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.
Apparently police are accessing the network via their personal devices. I highly doubt their security practices online are any better than this. I wouldn't be surprised either to see things that chinese manufacturers do such as intentional back doors.
Overall this goes from disappointing to fairly repugnant.
Allegedly you can buy credentials on the darkweb to perform national searches. Might explain why some of the logged reasons for recent searches were “LMAO”
The normal explanation is plenty, unless you’ve never met, read about, or heard anyone talk about, law enforcement officers (who are human beings - for better and for worse).
How many of us have had coworkers who put something like that into a commit message? And that's a message that's at least notionally supposed to be helpful to you or your coworkers, rather than existing purely for the purposes of oversight you don't want in the first place.
I would expect law enforcement coworkers to understand the law, department procedure, and public requests for their data. That’s expecting too much from the academy, I guess.
Those that fail to meet standards should be fired to spare the taxpayers from the lawsuits coming from AI-assisted complainants.
It’s also too much for Flock’s YC-funded technology to implement a field filter that rejects “LMAO” as a valid request.
At the very least, your local staff’s nationwide stalking credentials being harvested by phishing and abused by others should carry criminal negligence penalties. Governments should pass that liability onto this YC-funded startup company.
This meme will not die, and here you can see it blossoming into something even weirder.
There is one (1) case in the literature, back in the early 2000s, where a department rejected a candidate as overqualified based on a cognitive assessment; the rejected applicant took that department to court and lost.
That's it; that's all the evidence.
Against that: most police departments around the country administer written tests with general cognitive components for which there is a floor score and no ceiling (the POST, the NTN, &c). And virtually no departments --- none I'm aware of --- administer IQ tests.
From all this, we've now got "a federally protected right"?
Literally the only thing you know here is that one department didn't like one candidate and came up with a reason to deny him based on cognitive overperformance. For all you know, they didn't like his hair color, and came up with an excuse. And that's it: out of over 15,000 police departments in the US, almost 1,000,000 sworn officers, and over 25 years, this is the evidence you have for the claim that there's an enshrined "right" to reject police officer candidates who are "too intelligent".
It's an Internet urban myth. I'm just stepping in to call it out as such.
killbot5000 · · focus · HN ↗
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
wat10000 · · focus · HN ↗
NichoPaolucci · · focus · HN ↗
If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.
Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.
sixothree · · focus · HN ↗
Overall this goes from disappointing to fairly repugnant.
iAMkenough · · focus · HN ↗
DANmode · · focus · HN ↗
wat10000 · · focus · HN ↗
iAMkenough · · focus · HN ↗
Those that fail to meet standards should be fired to spare the taxpayers from the lawsuits coming from AI-assisted complainants.
It’s also too much for Flock’s YC-funded technology to implement a field filter that rejects “LMAO” as a valid request.
At the very least, your local staff’s nationwide stalking credentials being harvested by phishing and abused by others should carry criminal negligence penalties. Governments should pass that liability onto this YC-funded startup company.
DANmode · · focus · HN ↗
Reasonable people would expect what you expect. We are not reasonable people.
tptacek · · focus · HN ↗
There is one (1) case in the literature, back in the early 2000s, where a department rejected a candidate as overqualified based on a cognitive assessment; the rejected applicant took that department to court and lost.
That's it; that's all the evidence.
Against that: most police departments around the country administer written tests with general cognitive components for which there is a floor score and no ceiling (the POST, the NTN, &c). And virtually no departments --- none I'm aware of --- administer IQ tests.
From all this, we've now got "a federally protected right"?
DANmode · · focus · HN ↗
Feel free to consult an attorney.
Edit: I thought the case went further up - but, “persuasive precedent” for other jurisdictions now exists all the same.
Edit2: since I’m seeing the username of someone with a decent clue,
> and no ceiling
was there one on paper for the hiring standards of the dept in the case in question?
Does that matter?, if there’s no legal issue with using it as a disqualifying factor? - for any candidate - whether or not they even score well?
tptacek · · focus · HN ↗
It's an Internet urban myth. I'm just stepping in to call it out as such.
DANmode · · focus · HN ↗