A Vendor Pitches Face Search on Flock Footage (09/29/2026)
- › VIDIZMO pitched a Tennessee police department on pulling Flock camera footage and license plate data into its own platform for facial recognition.
- › Flock's chief executive says the company will not add facial recognition to its devices, and VIDIZMO says Flock was not involved.
- › San Francisco kept its license plate readers with new audit and data transfer rules, and the EFF says the policy has no warrant requirement or deletion deadline.
- › Glow Security found more than 13,000 screenshots from 343 companies' private work posted to public GitHub repositories, many by AI coding agents.
- › German customs investigators read WhatsApp and Signal messages by linking their own computers to suspects' accounts.
A company that declines to build a capability has not made that capability impossible, and today’s lead shows how little the promise can be worth once the data leaves its system. Flock has said repeatedly that it will not put facial recognition on its cameras. A different vendor is now telling police it can take the footage out of Flock’s platform and run facial recognition on it somewhere else.
Top 5 Critical Privacy Alerts
1. VIDIZMO Offers Police Facial Recognition on Flock Footage
Video analytics company VIDIZMO pitched the Johnson City, Tennessee, police department in May on exporting footage and license plate reader data from Flock’s platform into its own products for facial recognition, behavior prediction, and demographic classification, combining Flock and Axon data “into one searchable platform,” per 404 Media. Flock chief executive Garrett Langley has said, “We will not add facial recognition to our devices,” and VIDIZMO’s chief executive, Nadeem Khan, said Flock had not been involved in or informed of the integration. Khan described facial recognition as “the way the world will have to be,” according to a follow-up from 404 Media.
Operator Note: A vendor’s restraint only covers what happens inside its own product. If you operate cameras or share footage with a partner, your contract has to say what the recipient may do with it, because the original vendor’s policy stops at export.
2. San Francisco Keeps Its License Plate Readers
San Francisco decided to keep its automated license plate reader network with a 30-day deadline to move data from the vendor’s servers to the city’s, better audit logs, and larger penalties for abuse, per the EFF. The EFF points out that the policy has no warrant requirement for searches, no deadline for deleting the data, and no requirement that officers record why they searched, and that “moving data is not deleting it.”
3. AI Coding Agents Are Posting Private Screenshots in Public
Glow Security found more than 13,000 screenshots from 343 companies’ development work in public GitHub repositories, including personal information, credentials, and unreleased products, per The Register. Because GitHub has no API for attaching images to a private pull request, agents show developers their work by putting the screenshot in a public repository instead, and about a third came from a screenshot tool that creates its image repository as public by default.
Operator Note: Search public GitHub for repositories owned by your developers’ personal accounts that hold screenshots, and set a rule that agent-generated images go to a private store your organization controls.
4. German Customs Read Encrypted Messages Through Linked Devices
Germany’s customs investigators connected their own computers to suspects’ WhatsApp and Signal accounts through the apps’ device linking features, reading messages without breaking any encryption, per Schneier on Security. Access came through physical access to a phone, intercepted verification codes, or a state-sanctioned phishing attack.
Operator Note: Anybody who can link a device can read everything that follows, whether that is police or a criminal. Ask staff who use these apps for work to check Settings, then Linked devices, and remove anything they do not recognize.
5. UK Social Media Restrictions Take Effect in March 2027
Culture Secretary Lisa Nandy announced rules that will restrict social media for under-16s from March 2027, with live streaming and contact from strangers switched off by default for 16 and 17 year olds, per Biometric Update. The model relies on declared age range signals similar to the Apple and Google app store systems instead of verifying each user’s exact identity.
Additional Privacy Alerts
Regulatory Fines & Enforcement Actions
- Florida asks a court to stop ChatGPT from acting human with children: Attorney General James Uthmeier also wants OpenAI blocked from developing new models without independent safety reviews. The Decoder
Identity & Biometrics
- Social Security puts 105 million accounts behind a digital identity layer: The agency is becoming a test case as Login.gov moves toward being a common gateway for federal services. Biometric Update
- Signal completes encrypted local backups on every platform: Version 8.30 brings the feature to iOS and desktop. BleepingComputer
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.