logoalt Hacker News

License plate reader searches should require a warrant

328 pointsby apwheeletoday at 2:43 PM198 commentsview on HN

Comments

cmiles8today at 2:57 PM

Either it needs a warrant or it’s fully open and people can start creating websites showing the movements of local politicians.

This middle ground that municipalities try to carve out where it’s fully open to police without a warrant but not subject to FOIL laws doesn’t appear tenable for much longer.

There’s been too many cases of police officers stalking exes, poking around the data for fun and such so it’s clear police cannot be trusted with the data without better court oversight.

It’s certainly a very powerful investigative tool, but needs solid 4th amendment protections. The Supreme Court’s recent ruling on geofence searches of cell phone records is a good indication on where the Supreme Court’s head is at on this sort of thing, where they said no you can’t just do blanket data dumps like that without a warrant.

show 15 replies
malwrartoday at 2:53 PM

It frustrates me when people call them license plate readers. I guess you need to call them something, but they are general-purpose internet connected cameras. They will do whatever their firmware tells them to do, and could be reprogrammed at any time by anyone with access. No one expected doorbell cameras to join a mass surveillance network, but later the manufacturers added that feature. Why do we treat these cameras like they can do only one thing?

show 7 replies
Cider9986today at 4:48 PM

A warrant is better than no warrant, but:

A warrant requirement is not a reasonable bandaid to consider allowing mass spying. There should be no mass spying by default.

A warrant requirement makes sense for something like the locations of customers on cellular networks, because, although it should be improved, it's been built into the tech.

When you make the optional choice to create mass spying, safeguards do not make it acceptable.

delichontoday at 3:10 PM

This is a hole in the Constitution that would be better patched, at least with statute, better with an amendment. The fourth amendment says

  The right of the people to be secure in their persons, houses, papers, and effects...
Who is "their" here? In terms of property rights it's the people who own those digital "papers". The individuals who that data is about do no maintain or control that data, and could not destroy it, meaning they do not functionally have property rights over it. If I write in my notebook that you have blonde hair, the notebook is still my property. There isn't anything I could write about you in it that would make it yours (other than maybe "I hereby give this notebook to Joe Bloe").

Attempts to interpret the Constitution otherwise are, IMHO, attempts at good policy, but unstable as law. So we should fix it either by giving people property rights to that data (so that they can destroy or change it without permission) or to explicitly require warrants for access to PII owned by third parties.

show 3 replies
throw7today at 3:13 PM

Good article. It's a sober look at where we are at.

We lost a lot of strong privacy rights we had with landlines when we shifted to cell phones.

We're actually slowly creeping into pre-crime territory. You could have AI searching for possible pre-crime candidates based on unknown identity in the area, disparate pattern to usually movements, etc.

show 1 reply
arjietoday at 4:55 PM

Warrants for historical search with warrant-free flags for ongoing issues seems like a nice middle ground. Convincing. Good article.

It seems that would easily impede a lot of abuse and it’s straightforward to believe that historical data is rarely so urgent as to not require a warrant.

A matter of defining historical as a sufficiently old enough thing but that seems feasible.

metalcrowtoday at 4:52 PM

I do wonder though if the data retention should be restricted at all. This brings up a very good point that even old data (months or more) can be vital to cases or to the defense, but is there any downside to it that would make it worth restricting? And how long?

thaumaturgytoday at 4:51 PM

There is another middle option that I would have liked to see the author discuss: requiring either a case number or a CAD ID, instead of a "search reason".

In my conversations with law enforcement (mostly at management level, chiefs of police), all of them have had reasonable-sounding objections to a warrant requirement for a search, but zero of them have been able to come up with a reason why a case-or-CAD ID requirement isn't workable. Generally, they argue that in practice obtaining a warrant can be too onerous in time sensitive situations, and can be harder to obtain than the public realizes. Two popular examples are in kidnappings (time sensitive) and missing persons (difficult to obtain).

A case number or CAD ID however simply requires that the details of either a public call for service or an active investigation are associated with the historical search. It closes the door on officers' hobby searching.

Andrew's blog post does note the problems with oversight, which also match my experience, so this isn't a perfect fix. But it will go further in conversations with law enforcement for people that are trying to thread the needle on making "safe" mass surveillance.

(I am personally opposed to mass surveillance in all its forms, but arguing only from that position pretty much immediately excludes me from policy discussions.)

show 1 reply
Zaktoday at 3:20 PM

I don't like the article's tone of inevitability:

> I think cameras in all public spaces are going to happen. Imagine Ring comes out with a nicer camera system for homeowners....

Indiscriminately filming people in public places is illegal some places, e.g. Germany. Allowing the creation of large networks of cameras surveilling public places is a choice.

show 1 reply
giantg2today at 5:00 PM

Collecting and storing the information is the real problem. The focus on warrants is a distraction.

Access control (warrant) doesn't prevent a breach, and the system is not architected in a way to prevent internal abuse. The best way to prevent the abuse of data is to not collect or store it at all.

cm2012today at 5:12 PM

A warrant is too much but strict audit logs and other protections like that I agree with.

wiseleotoday at 3:37 PM

Here's a case study of what happens when this information is public (it's linked as the "data-driven" series). This information should not exist unless the plate is flagged and the reason for that is sufficient to obtain a warrant. https://www.eff.org/deeplinks/2026/04/open-records-laws-reve...

smalltorchtoday at 3:12 PM

Hotlists imply that actual search takes place the moment you pass one, so really, the illegal search happens before. Even if warrants were required to manually search.

Pxtltoday at 5:01 PM

There's a fundamental question: Is it legal for the government to blanket a public space in cameras and do whatever they want to the data that they collect from those cameras?

Is it legal for a private entity to do the same with their owned space (like a plaza or mall or office tower)?

Focusing on license-plate-readers seems like car-brain is causing the author to miss the forest for the trees.

smalltorchtoday at 3:40 PM

Monetization of public data for private profit is the heart of my qualms.

Why should it be possible for my bits be scooped up and sold for profit against my will.

show 1 reply
axustoday at 4:39 PM

The FISA court is a similar compromise.

corsendonktoday at 4:18 PM

They're more than just license plate readers. Much more.

speak_plainlytoday at 3:36 PM

A license plate is already publicly displayed information (and is in most jurisdictions not private property), and you're operating in a public space.

I know it's unpopular but I went from not supporting these sorts of systems to embracing them after seeing the positive effects in China.

For crimes that depend on anonymity, theft, assault, hit-and-runs, vandalism, illegal parking, etc., surveillance changes the calculation because the offender expects a higher or even a near certain chance of being identified/caught in China. I think this is a good thing. I also see no issue with someone breaking the law and receiving a ticket almost immediately.

With all systems, it comes down to the design. What sort of oversight is there, how long is footage stored, can it be used for specific crimes or expanded later, and are there mechanisms to correct false identification.

Done right, these systems work well. I would be happy to live in a society where street crime is rare enough that I can leave personal property anywhere, like a bike, without constantly worrying about theft. I think many fears about these systems come from dystopian science fiction and assume the worst possible implementation, rather than recognizing that technology can be designed with strong safeguards.

show 3 replies
mlsutoday at 3:44 PM

There is a concept in safety called the hierarchy of hazard controls. There is a ranking of hazard mitigations from most to least effective.

1) remove the hazard

2) replace the hazard with something less hazardous

3) isolate the hazard (guards, cages etc)

4) administrative controls (procedures, training, warning, etc)

5) PPE

Implementing some kind of judicial review for these panopticons is something like 4) in the hierarchy. It would be a good thing to have, but we can go far further. Why do we need this shit? Oh what so someone’s car doesn’t get stolen a few times per year? I think my values are in line with the founding fathers and most Americans when I say I would gladly give up a little bit of safety to not have a spy camera trained on me 24/7.

I would like more removal and less procedural controls. The cops cannot abuse a system that does not exist.

iamlepperttoday at 3:28 PM

I am for having it be completely open to the public, or require a warrant. The police should not have special privileges of information lifted directly from the public. Privacy cuts both ways.

GuinansEyebrowstoday at 3:42 PM

> Imagine Ring comes out with a nicer camera system for homeowners that has more comprehensive views around your house and is just as cheap. And we will ultimately be safer for it.

I wonder if people who feel this way will feel safer? In this scenario, you have a Ring camera system observing your entire property. Do you feel safer if someone comes onto your property and triggers an alarm? What if it turns out it's just a kid coming over to grab a stray frisbee? What if your neighbor noticed something needed a quick fix (say you left a can of paint open or something similarly benign) and wanted help in a neighborly way without first checking to see if you were home?

I guess we just take for granted that we live in a low-trust society. But we take that for granted at our peril, because the fear of a low-trust society is actively being exploited by people who want to sell individuals, businesses and municipalities the means to further erode that trust.

crimsoneertoday at 3:36 PM

Yeaaah for seeing Andy on HN. His stuff is always excellent.

cucumber3732842today at 3:49 PM

My jaded opinion is that Flock's mistake was marketing to police departments. In matters of criminal law the accused has these pesky things called "rights". The police have long violated those rights so there are reams upon reams of precedent reinforcing people's rights.

The accused has comparatively no rights when an bureaucrat is shaking them down and the accused is often a business rather than an individual it's easy to have sympathy for. Flock could've run their racket for many years, got much praise from the useful idiots, really gotten their system integrated and entrenched, if they'd have chosen that route.

Their mistake was believing in their own bullshit. They thought they could make it cheaper to solve crimes (at great cost to everyone's rights of course, but they thought this was acceptable) and make things better (or at least their definition of it). If only they had been slightly scummier and instead set out to help municipalities collect civil fines they probably could have gotten away without scrutiny.

kotaKattoday at 4:28 PM

funny question I have to pose now because I haven't thought about it yet in all the ALPR discussions and the like.

There are civilian enterprise uses of ALPR. Where do they fall in this? I don't even mean for mass data collection or even for parking enforcement. I'm thinking of like various car washes where they offer monthly memberships and their car wash portal system has plate recognition to tie your membership to your car. Or other enterprise access control applications where the ALPR pops the gates open instead of RFID tags.

Watney-0717today at 4:00 PM

[flagged]

ihswtoday at 3:20 PM

[dead]

CurbStompertoday at 3:37 PM

[dead]

AndersSandviktoday at 3:07 PM

[flagged]

show 4 replies
tamimiotoday at 4:12 PM

The best solution is to make your plate readable to humans but not cameras, now how would you do that I won’t reveal much else it will be abused, but think out of the pla.. box, I mean.