HeadFlash

Privacy

Senate hearing targets Flock Safety as wrongful arrest and 240 misuse cases surface

Flock's CEO skipped a Senate hearing where a wrongly jailed woman testified, researchers reported 240 ALPR misuse incidents and exposed cameras.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Senate hearing presses Flock Safety over wrongful arrest and 240 misuse incidents

The Senate Judiciary Subcommittee on Crime and Counterterrorism held a hearing on Flock Safety, the largest U.S. seller of automated license plate reader cameras, chaired by Sen. Josh Hawley with Sen. Dick Durbin as ranking member. Lindsey Isaacs testified she was jailed 13 days after a Flock camera placed her Dodge Durango two to three miles from an October 2025 crash that killed three people, though investigators sought a black Durango and witnesses described a maroon one. Flock CEO Garrett Langley skipped the hearing, sending a letter saying the company conducts very little oversight of client searches. The Institute for Justice cataloged more than 240 ALPR misuse incidents; researcher Benn Jordan described exposed camera interfaces and called false Langley’s claim that Flock has never been hacked.

Three takeaways from the Senate hearing on Flock’s camera network →

Hawley opens Flock hearing saying the surveillance network has probably heard of you

Senator Josh Hawley of Missouri convened a Senate subcommittee hearing titled Always Watching: Flock’s Nationwide A.I. Surveillance Network, saying its purpose was to figure out what is going on with the cameras. If you have not heard of Flock, all I have to say is Flock has probably heard of you, Hawley said. Lindsay Isaacs testified she was jailed nearly two weeks after a Flock camera mistakenly identified her vehicle as involved in a crash that killed three people, describing watching her mugshot on jail television. Senator Dick Durbin said Congress must balance privacy and security and needs to lead the way. The subcommittee invited the heads of four surveillance camera networks, including Flock CEO Garrett Langley; none attended.

U.S. Senators question use of Flock cameras and data access at subcommittee hearing →

Google DeepMind adds server-side memory with keys kept on user devices

Google DeepMind introduced a server-side memory architecture for its Private AI Compute platform, letting AI retain information across sessions and devices while encryption keys stay on users’ own devices. The platform runs demanding workloads inside isolated cloud environments called secure enclaves, but was essentially stateless, so context vanished once a task ended. Under the new design, persistent AI memory sits in dedicated encrypted storage, and when a request needs stored information the user’s device opens an authenticated, end-to-end encrypted connection with an enclave that temporarily decrypts only what is required. Google is publishing an updated whitepaper, security proofs, verification protocols and a tamper-proof public record of server software; an independent cybersecurity firm audited the system.

Google DeepMind introduces secure server-side AI memory →

Signal beta lets Android users register without a phone number for about $3

Signal, the end-to-end encrypted messaging app, now lets users optionally register without a phone number. According to lead Android developer Greyson Parrelli, the Android beta supports signing up by paying a one-time fee of about $3, a payment not linked to the Signal account, with the price varying by country and the fee meant to curb spam and abuse. Because no phone number is used, registration requires a username, and nobody can look a user up through their contact list by phone number. The iPhone version is still in the works, and Android users can try the feature early via the Signal beta on Google Play. Signal warns that a username must be maintained or someone else could take it and impersonate the user.

Signal introduces registration without a phone number →

A Lagos High Court ruled on September 14, 2026 that Truecaller cannot rely on a user’s consent to process phone numbers of people in that user’s contacts who never used the app. The case was brought by the Incorporated Trustees of the Data Privacy Lawyers Association on behalf of non-users, who argued their numbers were harvested, stored and disclosed without consent, violating their constitutional privacy right and the Nigeria Data Protection Act 2023. The court held that under Sections 26 and 65 consent must be voluntary, informed, specific and unambiguous, and rejected consent by proxy. Truecaller said it did not extract Nigerian contact data itself, that an optional Enhanced Search upload existed, and that its infrastructure is in India. The court denied the applicants’ ₦300 million damages claim for lack of evidence of material harm.

A Nigerian court says Truecaller’s consent doesn’t cover the data in your contacts →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches