Surveillance Expert: "I'll Go to Jail for This!" The Hacker Exposing America's Secret Spy Network
158m 32s
Flock, a privately owned surveillance technology company backed by venture capital and valued at nearly $900 million, has built one of the largest dynamic surveillance networks in the U.S., with over 335,000 cameras. These devices, marketed as simple license plate readers, use AI to track people, vehicles, and behaviors in real time, collecting vast amounts of data including facial features, clothing, and vehicle details. A cybersecurity researcher exposed severe flaws in Flock’s systems—such as publicly exposed API keys and insecure authentication—allowing access to nearly every American’s movement data across police, private, and municipal networks. The researcher found that Flock’s systems could be exploited to track individuals nationwide, even without a warrant, and that the company repeatedly claimed to be unharmed despite deliberate, repeated breaches. Flock’s platforms, like Flock Nova, can generate detailed profiles of individuals by linking disparate data points, creating a pervasive and often invisible surveillance infrastructure. Despite public warnings and technical disclosures, Flock downplayed or ignored the risks, claiming it had never been hacked. This raises serious concerns about national security, privacy erosion, and the unchecked expansion of private surveillance into public life. The researcher also highlights how data from everyday activities—like online searches or social media—can be used to predict personal life events, such as pregnancy, as seen in a 1990s case. With minimal regulation and poor cybersecurity practices, the technology poses a significant threat to individual autonomy and democratic freedoms, especially as it enables mass data collection and sharing across law enforcement and private entities.
Imagine setting your makeup, then forgetting it's even theirs. Meet new groupie setting mist from Mavily New York. Gel to mist technology locks in your look for up to 24 hours, with flexible all-day-gum v-grip. No tightness, no stickiness, no residue. Just plump, dewy hydrated skin that still feels like your skin. Try new groupie setting mist from Mavily New York. Today's guest is an expert on privacy, security, and the art of making people disappear. I started social media, so I didn't get to know him. That is my dead man switch. A cyber security researcher, he hacked into the world's largest surveillance network to understand how companies collect, store, and sell your data. Who the fuck decided it was a good idea to put the hands of our nation, the largest dynamics of our network in the U.S., to a start-up. With cybersecurity so poor, I hacked them in my free time for time. Now he dedicates his life to tearing down the lies we've been told about privacy, and has built an exclusive method for helping people vanish from their digital lives. Somebody had gotten a pamphlet in the mail for being an expected mother, being pregnant. Before she had known she was pregnant, he's based off the searches that she was doing. You got a lie on the internet that there's no point in giving away more information that you gain nothing from. In this episode we'll expose how much of your life is already on camera, unveil the players quietly getting rich, violating your privacy, and question if you have any privacy left at all, or if that was taken from you a long time ago. What was the most disturbing thing you found when you hacked into Flak system? Yeah. I will probably go to jail for talking about this for sure. Joshua, Michael. Welcome to the Jack Neal podcast. Nice to. Much appreciated. Yeah. Good place to start here. Now, there's been a trend all over social media, dozens of people in face masks and helmets going out on the street and filming themselves destroying Flak cameras, which are described by the people who make them as artificial intelligence automated license plate readers. Why are people destroying license plate readers? That's a very good question. It's because they're not just license plate readers. This is the way that Flak got their foot in the door to building the largest dynamics around the network in the United States. You know, if you say you're going to put up AI powered cameras that's able to ingest every single thing it views, and you could search it nearly endlessly, historically, people would not be very happy. But what is the best way to get around that? Well, tell people they're license plate readers. And now you could pitch these LPRs to police departments and municipalities, and they won't second guess it. It doesn't seem like you're setting up a dynamic surveillance network as per their patent. You're just trying to stop crime. You're just trying to read license plates. That's how they got their foot in the door to the massive growth of what we see today. And people are becoming less ignorant about it. They recognize that these cameras are not just LPRs. That is the friendly marketing term that Flak safety likes to use on them. So you said that people are figuring out that they're not just license plate readers. I guess what exactly is a Flak camera to you? A Flak camera is kind of like the watch tower at the corner of a prison. It is always watching. It's always tracking. And if you do something wrong, even if it's not something wrong, it can alert on you. So these cameras, these license plate readers, LPRs, which is what their market is, have the ability to search using AI, and Flak calls this freeform. So I could write in, and say, find me an individual with a cowboy hat and a Ford F-150. And it will track through every single camera that that person has access to, because they could have access to the camera's nationwide or even just to their own municipality, and it will find that person or any scenario that matches that description. You could write, "Wash me on the back of your dirty car," and it could find that. You could search pretty much anything inside video, anything that ingest, historically and presently, and then create alerts for them. They are what the East German Stasi would have had wet dreams over for their national intelligence agency. So give me a breakdown of like who has access to Flak's network, how many cameras there are around the world? Like, why do people see this as such a big problem and so invasive? And when did this all kind of happen? Well, I started my research last year in June on Flak, and to be candid, it didn't start really picking up in the public up until early this year. But you have a couple questions there. Who has access to Flak? The people that are meant to have access to Flak are either people that own these cameras, whether it's community or a business, or municipalities, police departments, federal agencies, etc. And they have different scopes. So these police departments have the ability to set these alerts to search for people, to use them for investigations, practically nationwide, and the communities and private businesses that have access to it can see their own network, their own cameras, but they don't have the capability to see nationwide like the police would. And so they really start to expand and grow because you come to realize that people are trading their privacy for what they think is safety, but it doesn't actually solve any crime. I mean, we still have so many people missing, so many missing children, and I think people are starting to get outraged because of that. Just don't get outraged because every moment of their life is being surveilled, not targeted surveillance, but move to generous surveillance, where you are assuming that you've already been surveilled, regardless of doing anything, and it pisses people off. Name one person, and I couldn't tell you what, you would hire a private investigator on themself and then send all this information to the police. That is essentially what these cameras are doing. They're paid for by our taxes, installed without our consent, and then tracking us. So when they rolled out initially, I think it was 2017 or 2018, right, 2017, I believe. Got it. And the people who were trying to, I guess, advocate for flocking the early days, they would go to maybe a city council, something like that, and they would tell them it was a licensed plate reader, and essentially they've added new updates and new tech to flock, to expand it to be more than that. Is that the case? Essentially, but they also have a patent that describes everything that they were planning to do in the first place. So they, again, sell you a licensed plate reader, and they market it as very friendly. The camera does weigh more than this. Another patent for a dynamic surveillance network uses an AI model that classifies it for different unique things. It's able to review and classify people, vehicles, animals, and bikes. And so, yeah, you could call it a licensed plate reader. It does do that, but it is more of a general surveillance node than anything else. And how many are there? There's over 280,000 of them. 335,000, if you include decommissioned, and they're even in places like South Africa. You know what's the scariest part, is it's not just flock cameras, because the cameras themselves are what people see, but they have something called a Wing Gateway. A Wing Gateway is essentially a networking station where you're able to plug in your existing IP cameras, so think of the ones there inside of gas stations and stores and schools. You plug your cameras into their Wing Gateway, and it turns any device into a flock device. They are able to set alerts. They essentially become another autonomous surveillance node, disguised as a camera that you would never think as a flock camera. So if I'm a gas station owner, not a camera, just to make sure people aren't, I don't know, when gas, is that something that I consent to tap into flock network, or does their technology just automatically utilize it? As you do have to consent to it, yeah, then make it really easy. They give up Wing Gateway's for free. You have to think their business is a dynamic surveillance network. And so more nodes makes their company more profitable. You can have a nationwide dynamic surveillance network with just three cameras. So then we'll then get in the better. And then at this point, when you see people tearing down flock cameras, which I don't advocate for, by the way, I believe the correct way to ameliorate this issue is through policy, especially through your local city council. It would make sense that they start moving towards more disguised cameras. They may not necessarily look like they already known flock cameras. So you said that the gas station owner, he does consent to it, but how would they have access to all these secondary cameras, like what's the benefit for him to consent to? Well, he has a police watching his cameras at all times, practically. They could be used to set these alerts. It essentially could be like having a private security guard in a way, but much more dangerous than a security guard. Right. Okay. So business owner would be incentivized to allow that because it theoretically offers them more protection. No. I mean, I think it's Academy, I appreciate it.
Academy Sports and outdoors has their inside cameras integrated with Flog. And so, if you walk into a store of this, it could do the detection of people and find out if you're there. Now, if I drive or walk past one of these license plate readers, a Flog camera, what data do Flog cameras actually collect? You kind of give me a few examples, but does it go deeper than that? It's really interesting because what they publicly claim they collect and what they do collect is extremely different. And it's just a bunch of legalese and rhetoric abuse. The cameras collect everything that is in their field of view. But the collection is only half the problem. It is the software behind it. It really stems the issue. Because you imagine, we're recording now with cameras, but these cameras don't have facial recognition. They don't have the ability to livestream 24/7 and then create alerts on these individuals or vehicles or people or animals or whatever you would like it to be. So, to give you a rundown what these cameras are meant to collect is one, the license plate. Two, any likeness of vehicles. So, in that patent, it covers make, model, I believe color, roof racks, any unique features of it, stickers on the vehicle. And so, you don't even need a license plate to be able to track an individual or to track a vehicle. For people, they do race, height, gender, weight, clothing that you're wearing, a peril. You could even have say somebody holding up a no-king sign in your research this. They collect just about everything that you can imagine inside. What is that frame? And they connect to a bunch of different systems. On their website, this absolutely cracks me up because it's something only flock would do. Where they try to do this slimy marketing. They say, "Our cameras do not collect any PII." But your cameras take pictures of license plates. And license plates are directly tied to a person's identity. Whether it's going to be your name or your address or maybe your business which adds one extra layer. They also say they don't do facial recognition. But in their patent, they actually call out using facial recognition to identify somebody that's stole from a store, a candy bar from a store. And so, while it may not be present in that cameras today, it definitely tells you what they're probably going to move towards. And it's this kind of slimy, yes, we do this, but we also don't try to work around and market their company that makes people distrust them even more. So, how many hours of footage exists of me right now that I've never seen that is a part of flux network? You know, probably only a few minutes. A few minutes. Only a few minutes. If you think about it, you pass these cameras quickly. You're not just hanging out in front of one. I'm more than likely. But those few minutes could span back up to five years. So five years of your historical movements simplified in two, five minutes. And how long did they keep that data for you? Said, wow. Yes. So, this is again, one of the slimy things. They say the default retention is 30 days. So, the cameras will record and store the data for 30 days. After that, it's supposed to be deleted. My fellow researcher and good friend, John Gaines, he found 51 different vulnerabilities in these cameras, the hardware. And when we were booting up the camera and looking through the storage of it, there was still pictures from when it was being tested in the factory and created. So, I'm not sure if they actually delete that data after 30 days. Otherwise, they probably would not have the footage from the factory. But they say that's the default. They then offer packages to increase the amount of time. So, then they offer one year. They offer, I think, three years and then five years. And this is selected based off of jurisdiction. I'm not sure if we clarified this already, but flock is a private company. They are. They're a private company VC backed. I think close to $900 million, where they ate and a half billion dollar valuation. And they're what we consider a startup. I think it's dangerous to trust a startup with the largest dynamic surveillance network in the United States. So, if I gave you my license plate number right now, what could you pull up about me? Well, pretty much everything. I give you an example. These kind of devices, I'll tell you about flock Nova. I won't even give you personal anecdotes. flock Nova does either get the same thing. Is there a person intelligence platform? Dubbed, search once, see everything. He'd use these same license plate lookups and then uses it to extrapolate data about your life. You're using names, your emails, your addresses, your phone numbers. All the accounts tied to these identifiers, the people you're associated with. It is really quite a crazy tool because nobody really knows about it yet. They see the flock cameras and they think, "Oh, I'm getting recorded." Though do they know that exact same camera feeds into a person intelligence platform that only sometimes requires a case number. And what's a person intelligence platform just to give me that? It's where you're able to search for people. Find data on people. And it's really a unique mix that they have going on. For example, there's a company called IDI and they do the same kind of data platform that flocked to us, but it's not meant for police. In the state of California, pulling the registrant owner could be a little bit more difficult to be able to find out who owns a car. And so while they have so many of these data points, your email addresses, your phone numbers, your emails, they have to still find ways to get more data than that is necessary. And so what is the solution if you're not able to pull the registrant information of your car Jag? Well, why don't we buy financial data from companies that are fixing tires, doing oil changes, all sorts of these maintenance stuff with your vehicle? And then we could tag this as an operator, the operator of the car, not just the registrant owner. And so they use financial data to be able to find who actually drives your car, even if it's not you, could be your daughter, could be your son, your wife, you own the car, but knowing that you own it is not enough. We need to know more. So flocked over. That's just the person intelligence platform. That's not like cameras in the sky, right? No, that is aerodome. Also, before I ask you about that, I should ask, do you have data for like the average person, how many of like flock cameras they pass on average per month, per year, something like that? It was like 3.17 at 3.7 cameras daily. So the average person passes three cameras daily? Yeah. Got it. What's unique is they both scanning 20 billion license plates a month, 20 billion reads. There's only what 360, 380 million Americans, only 160 million commute to and from work to their own vehicle. That is a lot of data reads. And so, you know, I say three points something. It would imply that some people are getting picked up quite a bit more than that. And you said that there's another network that's not just flock cameras, but it's actually in the sky. What was that called? Aerodome. Is that owned by a flock safety? It is. Yeah. It's actually really unique. They got a permit to be able to fly. I think it's 400 feet instead of 200 because you can't hear the drone at that height. And the point of it is, if an alert goes out, they're able to deploy these drones at sent-on rooftops and track or follow these individuals, even with license plate readers. And it's supposed to be drone as a first responder. How many of those are there? About 400? 400? Got it. Yeah. They're relatively new. As of when, do you know? I think they started the program a little bit over a year ago, but they're not taking it off very much. That's interesting. I'm not sure if you mentioned this already. You talked about this idea that if someone has a camera at a gas station, they might sign up to be a part of flock's network just to have like better surveillance for their company with the police. But can flock watch me through my neighbor's ring doorbell camera? Quick question. If you're someone who uses AT&T Verizon or T-Mobile, did you know that for 99% of you, your data has been breached in the last five years. Now, this might not seem like a big deal, but your carrier knows everywhere you've ever been, everyone you've ever called, and every meme or picture that you've ever sent. And all that data has been stolen or sold to private companies. And that's exactly why I switched to Cape. It's America's privacy first mobile carrier. Same reliable cell service you'd expect from any other provider, but instead build around protecting your privacy instead of profiting off your data. Now you might not know that every phone has an identifier called an IMSI. That's permanently tied to your SIM card. This is what carriers add networks and hackers use to track you, but Cape automatically rotates that identifier every 24 hours so you look like a brand new consumer every single.
day. And any call, text, or metadata you generate automatically gets deleted after 24 hours. They also give you two extra phone numbers with your plan, so instead of giving out your real number to every app, website, or service that asks for it, you can just use your secondary line. And right now, Cape is offering early adopter pricing at just $70 a month, usually $99, and that price is locked in forever. So just use the code JackNuel33 for 33% off your first six months, or you can go to JackNuel.com/CAPE. Again, that's JackNuel.com/CAPE, or you can scan the QR code on screen if you want to carry your that actually protects you instead of selling your data. But anyway, guys, back to the podcast. Can flock, watch me through my neighbor's ring doorbell camera? Ah, technically no. No, they said they were going to, and then the Super Bowl ad went out with ring, talking about detecting some dog or something. And if you were like, Hey, what the hell? You can detect a dog. You can detect a whole lot more than that. So they ended up scrapping that integration and they walked back the conversation with flock about that. I'm pretty sure Garrett Langley, which is the CEO of flock, talked to about this same thing in an interview and said, You know me and the CEO of ring our friends, start our companies around the same time. We're not opposed to trying this again in a later date. So before you know it, your ring doorbell might just become another surveillance note, but it kind of already does that. It does have facial recognition, and you're able to set it off or turn that off if you're the primary person in that house. And it could still be shared with police or whatever you'd like to do with it. There's so many cameras nowadays. Microphones can flock to access to. It's only ones that people opt in on. That's a great question. I couldn't tell you as much for the microphones. I could tell you they have a device called Raven and Raven is their gunshot audio detector. And I think this is the slippery slope of all. In fact, it is just a sheer cliff if you're not careful because it's extremely dangerous. This gunshot audio detector is put up pretty much in and mass in places. It's able to geolocate wherever these sounds come from. And the thing is to be able to hear gunshots. It's kind of the same way your phone has to listen when you say, "Hey Siri, it has to be listening." And so it is constantly listening. What does that mean if you walk by it and say something that maybe you're saying confidence to you or your friend or your wife or your husband, there wasn't meant to be said or heard by somebody else. If we see this happening in the same way they did their license plate readers, where they slowly roll them out under nice marketing terms, you know, we read license plates. Oh, we're just a gunshot detector. And then in just every single thing that is in that video footage and is able to be alerted on and tracked and used to surveil people and searched, I think we will lose the ability of public utterance. Because what is stopping them from saying, well, you can search for anything that somebody said around these cameras. If they add audio integrations into all of their cameras, which is very cheap, adding microphones, there's not an expensive thing, especially if it's other IP cameras. It would be the final step into soft authoritarianism without ever clearing it. Because public utterance is gone. So now you imagine you have AI being transcribed or transcribing everything said in the vicinity of this camera. You can step inside an elevator. These are connected to a flock network if they choose to do so in the future. And then somebody can search out of anything that you said. Now, I remember listening to I, I think it was John Keriyaku on a podcast, talk about this idea that maybe the NSA or the CIA had the ability to just listen to your phones, listen to your TVs, like track all this stuff already. From what you know about like government intelligence as opposed to flock, like why is this a big deal? Is it that those things aren't able to be maybe utilized in a court of law if they're gathered through intelligence? But with a private company like flock, they are. Or is it just the number of people with clearance to access the camera footage or the audio? Like is that what's concerning to you? Like how do you view this? You have to think that I talk about this, especially when people talk about getting hacked on iPhones. The NSA is a very small group of extremely intelligent handcrafted engineers with brains that are so malleable, full of plasticity that they could do just about anything. But it's such a small group and often their time is spent targeting specific individuals. When it comes to something like flock, well, the access and the ingestion of people is a much, much, much larger scope. So we know the NSA has done horrible things when it comes to privacy as an individual, you know, intercepting emails and phone calls on mass to be able to provide national security, even though it's found to be illegal. But the thing with flock is it's not just, you know, 100 extremely well-audited individuals with clearances that have served doing this for decades. It is thousands or hundreds of thousands of police officers using a tool that they may not be fully aware of the consequences of. That is the scope. And yeah, the NSA collected data on nearly every single American. But flock does the exact same thing and their cybersecurity is way worse than the NSA. Would you say that's accurate that the NSA could just listen to this conversation right now, but flock is setting the precedent in the future for hundreds of thousands of police officers to be able to listen to this conversation right now. Yeah, I mean, it seems feasible. I would not be shocked. If you had cameras in here and you said integrate them with flock, they'd be able to listen to it if they added the feature. Before we get into your work around this, I want to ask, can the police track someone without a warrant? Yeah, yeah, of course. Can you break that down for me? This is actually one of the very big issues that we see today. And it comes with ad technology. So traditionally, if you want to track somebody, you would have to get a warrant to be able to track the cell phone and then they'll geolocate it using three towers. And then you can see every single ping of your location, recurrently, however long it would like to. But this required a warrant, because it is long-term location tracking, how they've gotten around it and actually what flock Nova cells access is using what we call made, so mobile advertising IDs. They have finally passed or had a case where they said it was requiring of a warrant to be able to use made to track locations. But I don't think we've seen any big changes for what flock Nova does and what flock does is you put in an individual's email or phone number or device identifier, it pulls the mobile advertising ID. And so the location on your phone from all the apps that you have enabled essentially is shared with them, long-term, persistently. You don't need a warrant for this. Garrett Langley actually was slimy in an interview and talked about this exact same thing. Oh, well, no, no, no, you need a warrant to be able to track these phones, no, you need a warrant. Knowing damn well, his company allows for you to track somebody through their mobile advertising ID. So your weather app or Snapchat or Uber, these are all apps that you typically have your location on for. They take it and they sell it through real-time bidding. That kind of unique identifier is traceable back to you. I mean, if you think about it, all I have to do to find out who you are is say, where is this person go at two in the morning? Oh, well, they're at this house every single night, two in the morning. Well, what do they work? Let me filter from 8 a.m. to 5 p.m. on day to Friday. Why they work here? Well, the individual that lives at that house and works there must be Jack. Right. How anonymous is that? And it's just location data from the, I can't remember the term you use, but mobile advertising ID, mobile advertising ID. Oh, no. I mean, they use the, they use the advertising ID for location data for geolocation, but your mobile advertising ID could contain hundreds of pages of records, especially when they're put together in one specific company. I mean, this is the point of advertising. It is meant to predict what you are feeling, take advantage of you and sell you a product. It kind of is like a hypnosis in a way, which is crazy. What are some of those things besides location data that they keep track of? Well, obviously your age, your gender, estimate age and gender. The preferences you have. So if you like, go to a Ford website instead of a Subaru website. These kind of small things. Do you have dogs? Are you pregnant? Do you even know if you're pregnant? This is a really interesting thing that I believe happened in the 90s, early 2000s. They were using advertising tracking back then as well. And somebody had gotten a pamphlet in the mail for being an expected mother being pregnant. Before she had known she was pregnant, is based off the searches that she was doing. Right.
tell me that's not crazy. Finding out that you're going to be pregnant, without even knowing it. Because of a pamphlet that comes in the mail. Now, I may be citing this an improperly, but I remember that story. I remember that story. That was, I'm glad you recalled that. That was a crazy woman I read that for the first time. That was in the 90s? 90s or 2000s, I believe. I cannot imagine what it's doing now. Yeah, I mean, pull your report. There's about a thousand different data brokers out there. I think I shared with you axiom axiom and you can pull one from them and they'll give you 90 pages of everything about you. It was interesting. I did that. I forgot. I forgot the name of it. So I couldn't go back in my email and check it. But so if someone wants to see what data they have on them, they go to axiom.com. Is that it? Everybody spells it AXC IOM, where's ACX IOM ACX IOM. And they own the domain for the other spelling as well because people would misspell it so often. But yeah, you would go to axiom.com and you could pull a list, you'll request it from them. And they'll send you a massive PDF with just about every single identifier that you have for advertising. Yeah, like I said, I mean, are you likely to buy Subaru? Yes or no? Are you likely to buy Ford? Yes or no? What is your age? What do you like to do? It's really interesting to think about. We share so much information that people are really not even cognizant of because you don't see it physically. But it's being harvested and it's being stored and it's being used. You know, this is my own no conspiracy theory. Today, the secret service has hidden so many people. What do they call it? The witness protection program with a 100% success rate of people that followed those rules. I wouldn't be surprised if within our lifetime we see this get completely demolished. Because if you think about it, yeah, somebody changed their name. They changed the way they look. They changed a dozen different things. But what if you were able to pull their old, their old advertising report with 90 something pages of traits about them? And then you find somebody else that matches after they disappeared. Wouldn't that be great? If you were going to find Epstein, you could probably do it through that method. And what's the method exactly? You would pull their advertising data into what exactly? Pull their advertising data. See what their unique identifiers are. Yes, snows, maybe age, location, height, weight, yada yada. And because there's so many data points, it'd be improbable for, you know, there to be too many people that match exactly that. And with the power of AI, you know, you could be able to do things in a second they used to take years. That data ingestion is going to be crazy. You told me a story off camera and I can cut this if you want, but so how did you utilize like a similar method to this? So this is when I was out of his first starting accident, like publicly, trying to do outbound sales. And I was like, well, you have to come to people with results. Otherwise, they're not going to understand. And privacy is also a fickle thing, but these people are extremely targeted and being an executive with the Department of War also means your data is extremely necessary to protect. What I ended up doing was using all these online data brokers and tools and unique trade craft that we have to find and track people so that we could make them digitally disappear. I pretty much mapped out everything about his life. Him, his wife, his family, the same way that somebody that wanted to target him would. And so I could explain it to him and say, look, these are all the things you have out there. I was so fresh in this. I was, I offered to do it for free, actually, because I thought this would be a great connection. Once I got everything put together into this PDF, I noticed there was a couple unique things about him and he had a obsession with fish tanks. So he had an account on a fish tank form that was extremely niche. And to show him what a real threat actor would do, what spear fishing, I created accounts on that fish tank form. And then cloned the password reset and notification email and then showed him that I set this up to be configured to go to my domains and steal your cookies. So if you clicked on this and logged in, I would have access to your Gmail account. And so this is actually how threat actors work today. And I thought that would be the best method to show him of actual risk and why would love to help him digitally disappear. I mean, you're the executive at the Department of War. And so you probably should have a little bit better operational security than your handling today. I mean, who the heck has videos inside their house about fish tanks on a form? Oh my goodness. It's shocking to see how poor people's operational security is today. Obsec is what they call it. How long did that whole process take you? Like an hour and a half, two hours? Yeah. That's fascinating. And just to let the audience know a little bit more about you, what's the most important part of your story to understand why you care about flock safety and the work that they're doing being a threat to sovereignty? You know, I'm a privacy person, but the reason why care for flock safety is less about privacy and more for national security. They are one of the most egregiously poor companies when it comes to cybersecurity. And you have to take into account that they have data on nearly every single American in this country. I continued my flock research because I saw it as a national security threat that needed to be made aware of. People needed to be made aware of. You know, not every company requires themselves to be extremely secure. But if you're pulling data from nearly every single American movement data, geographic data, this is intelligence. And this is intelligence that other countries would love to have. I told you earlier that I think it was Marriott or Hilton was hacked by the Chinese party from 2018 to 2023, not for me and you, but in the off-chance of finding that two politicians from different countries or different areas have one overlapping night. It's not ever publicly recorded. And so intelligence isn't being able to directly hear the conversation per se, but see that there is movement happening. If they're willing to do that for a hotel chain, for the chance to know if two politicians are going to coordinate, what do you think they're going to do for a bunch of 24/7 live streaming cameras that tracks the heartbeat of our nation and every individual in it? And I found that API key publicly hard coded 53 times to the heartbeat of our nation. Right. So flock, the CEO came out and said, what was it? That they hadn't been hacked ever. They said that three times. But you've broken into flock system four separate times. Is that right? Yeah. But let me explain. This is called cybersecurity research. Hacking is a little bit different, even though it's the exact same thing. What I did is compromise their company and then sent them emails and explained to them how I did it, where the vulnerability is and how to fix it. And then they try to pay you a bunch of money in the five figures and give you an India, so you're unable to talk about it. You want me to talk about the four vulnerabilities? They're pretty crazy. Yeah. Sure. So this first vulnerability, actually I did in France and was the reason why I left France. I was on like a nine-month halt. I did three months in Argentina, three months in Peru, three months in France, and I found this API key on on flock subdomain. And what's an API key? An API key is essentially a password. So me and you log into our accounts with username and a password. But systems and computers when they authenticate with each other, they just have a super long like string of text and numbers. And it just uses that to authenticate something that's not guessable. And you're never meant to hard code these API keys. This is like a high school project level basic security feature. You do not hard code these API keys. And what's happening to hard code? Put it in the code itself. So if somebody saw the code or downloaded the code, or you served it publicly, people could read it and use it. And most companies have their code public. Well, some portions of the code has to be public. But I'll get into that with flock as well because they did it extremely poorly. So that first API key, they messed up my hold. They messed up my hold. I had to come back home because I was significant. This was that API key was referred to as a default API key for the system of Arc GIS. Arc GIS is a map. It's a map that is also an Excel spreadsheet. So we can add a bunch of information onto it. And so for flock, it could be location points where your car was seen or location points of when a vehicle was detected. It could be the live location of offices through their CAD, which is computer-aided dispatch or AVL, which is autonomous vehicle locators, because the officers locations are also on the map. It could be pretty much anything. They have 911
one calls in flock at flock 9-1 and it has transcripts and who called in the time. Everything that they encompass that API key had access to. Everything that flock does, all 5,000 police departments, 6,000 private communities and 1,000 private businesses would have been exploitable, readable through that API key. And so when you see something like that, that's why I tell you that they ruined my holiday. Because if I disclose this while I was in France, well, you know, they could try and come after me for espionage or treason or so many, any crazy thing because flock is a very litigious company. And so I came back home with the realization that this is probably one of the biggest cybersecurity failures of this decade. And the chance to be massive threat to our national security as a whole. So you've hacked it once, cybersecurity research got access to the API key and then you were able to get into all this data. If someone does it one time, are they able to access it permanently like access all the cams or if I didn't report it, I could use that key for however long it was set to not expire. But I report all the vulnerabilities to them so that they could fix it. You know, my data is in there, your data is in there. Cyber security research has done for public safety. And that is why I did it. You do not have persistent access unless I would have had persistent access if I didn't tell them. What's also crazy is they have been very laxed asical when it comes to talking with me. When it up happening is when I reported that this API key was publicly facing. I emailed them about it and the email chain failed multiple times. I had to keep following up over and over and over again. For a key that has data to nearly every single American, all the movement intelligence of nearly every single American, hard-goated. I had to keep probing them to reply to these emails and then they invited me to this thing called hacker one for their bug bounty program. One to pay hefty money and sign an NDA so you could never talk about it. And I turned it down. I said, this is not how you fix cyber security as a whole. You make people aware that a company holding data as sensitive as yours can still make this high school level mistake 53 unique time. Hard coding, the heartbeat of our nation publicly. Now I told them I'm going to talk about this on July 1st because I reported to them in June, June 14th, I think, or 11th. If you don't have it fixed by then I will talk about this publicly so that you have to fix this. The data is that important to protect. And that was my first vulnerability that I reported to follow up a little bit later. I think it was November and I was completely everywhere for flock. In November, I found two more vulnerabilities I reported them. One is they authenticated at the wrong layer on their development subdomains. So in English, you log into an app and it serves all this content behind the scenes that allows you to use that app. They did that a little bit early before you would have to log in. So they authenticated at the wrong layer. And so for flock safety and all their applications, you know, the camera, madman subdomain, the hot list, the searches, everything. They serve their source code of a client side application early. So you could pretty much map out and enumerate every single detail about this company, how the application works, everything behind the scenes and it's back in on every single dev subdomain, which is also where I found that API key the first time. I reported this to them. I sent them an email November sent another email and they never replied back. I sent a third email and said, look, acknowledge me, acknowledge me that you have this report that this vulnerability report has been submitted to you. I sent it like five different people. And then I got a copy and paste email back, acknowledge, thanks for letting us know. There's some crap like that. At the same time, I reported them they had another credential issue. They had a subdomain called planner dot flock safety.com and dev dash planner dot flock safety.com. The purpose of this is you would log in to this page and you're able to see where all the camera locations are. This is not the same, same level access as that first API key to the entirety of the nation. It's much more scope. It's just these cameras in the locations and all the devices. But they had that exact same issue as before. They authenticated on the wrong layer. And so you or I or anybody was able to go to dev dash planner dot flock safety dot com or plan a dot flock safety dot com and get a freshly minted API key API token to access and find every device in the United States for flock safety. What was unique is when I found that it was on not only their production suite serving that API key. I noticed that since it was also in the depth suite, I have to pull the metadata regarding that key and see what it had access to and not the actual locations itself in the beginning. But you know, is this a production key? Is it a dev key? You start to realize they mixed their development environment with the production environment. So both of them gave me the exact same key that was meant for their production map, the production devices, which is typically not done like ever from a cyber security perspective. You're meant to separate this. In fact, most companies will lock the development subdomains behind a VPN. So the only their customer, only their clients or engineers themselves are able to access it. Because when you're developing something that's going to be issues everywhere, it's still product that you're working on. You have to push it from development to what is staging slash QA. And then you push it out to production. And so dev is a very fickle and sensitive site that needs to be carefully rendered access to. And they just left them open. And they just left it open. But the same scenario with that API key, the one that was essentially allowed to mint over and over and over again, every time you go to planter.flocksafety.com. I reported it to them at the exact same time I reported it when I was just telling you about had to follow up three times throughout November. And then finally got a copy and paste back. Yeah, I got it. Thanks for letting us know. They never replied to me if they ever fixed those. They really don't like me. And so I went back and looked to see if they did. And they didn't. When they're having next is I was pretty much finalizing my research on flock safety this time. You know, it had cannibalized months of my life. But I knew they had a product called flock Nova. When we talked about earlier, where it's able to find details about you and turn one branch into an entire tree of information. I found out that they had also made the same authentication mistake on flock Nova. And so you would try to like flock Nova.com and it just redirects. It doesn't give you access. There's all sorts of ways they try to hide this application. But I noticed they had a domain. I think it was flock demo.com or something. I hunted it down by reading through the JavaScript bundles that they served before authentication, which was a mistake and being able to enumerate the inside of their app. And so I downloaded all the source code for flock Nova. The exact same way I downloaded all the source code for flock safety. And I reported that to them in an email. It had December 11th, I think. December 12 December 6th, you know, never applied to me. But I saw later that they took the website down so that nobody could access it. And then in December 14th, there was a massive shift. Imagine setting your makeup. Then forgetting it's even theirs. Meet new grippy setting mist from Mabelie, New York. Gel to mist technology locks in your look for up to 24 hours, with flexible all-day comfy grip. Try new grippy setting mist from Mabelie, New York. Maybe it's Mabelie. And I sat there and thought about it for quite a while, noticing how horror the cybersecurity was. It was a systemic, recurring issue. They do not really care for cybersecurity is what I felt like and noticed and what other people felt and noticed. I mean, Senator Wyden put out a letter saying that flock is an egregious company incapable of securing the data for organians. On that day,
I pulled the entire device location of every single device in the United States from Flock Safety using that planner dot Flock safety dot com domain. And I never told them this and this was my bet. In October, I was in a video with Ben Jordan and John Gaines. John Danes is another substitute researcher, Ben Jordan is a YouTuber and substitute researcher and we he put out a video that said, you know, we hacked 80,000 police cameras, which is a hell of a title. I didn't come out the name, by the way, I would not name it this much. But they essentially slandered us. They slandered Ben and John over that video, but they will never acknowledge me. John ended up getting fired from his job after that video went public. He had started a venture capital backed penetration testing firm. He listed all the things he did on Flock in his resume and then shortly after that video went public. For some reason, they let him go. Who knows why even though they knew directly about his research, he was a stellar employee. He's absolutely amazing as I'm security. So from my understanding, you hacked four different times, I told them about the first three and then I emailed them each time and they barely responded. I told them about all four to summarize the vulnerabilities. The first one was an API key that gave me access to practically the entirety of the United States. So all 5,000 police departments, 6,000 private communities, 1,000 private businesses. I didn't pull any data from it. I chose not to even know how to access to like 50 something private layers. The second one was being able to pull the source code for Flock safety. The third one was re-menting these API keys for access to every single device in the United States, the locations of them, the network identifiers, etc. And then the last one was being able to pull the source code for Flock Nova, their people intelligent platform. So if I'm a hacker who wants to do damage to Flock system, perhaps the United States and I get access to an API key, what can I do and then if I get access to the source code, what can I do? Can you kind of break those down for me? Yeah. So the source code allows you to understand how the application works to find more vulnerabilities. There's a million and one small little details that you notice whether it's permissions, whether it calls to this API endpoint, whether it is whatever, it gives you a behind the scenes look of how this application works. And for hackers, what they'll do is go through analyze the code and find the vulnerabilities from the inside out, much easier than just doing it blind. For the API key, well, you could have done pretty much whatever the heck you wanted to. You could have started falsifying records in their system. You could start a deleting records from the system. You could have spied on practically every single American, whether it's a politician, whether it's going to be generals, whether it's going to be FBI agents, or like many policemen do, their ex-wives, that's what you could do with these API key. That's true. I did define intelligence officers. I did not. Or like not you, but like could someone have done that? Oh, more than certainly. You know, when I published about the default API key, I got traffic on my blog from North Korea, which is really interesting because North Korea only has one in-gress and egress node where they're able to travel and view the internet from. Typically, the only people that have access to that are the military. And a few hands select really, really rich people. So I thought it was unique to see traffic from North Korea on my small blog a few days after I wrote it, covering flock safety in the API key that gave access to tracking every American. Do you think that was like, oh, how do we do it? Moment or do you think that was like an OSHIP moment? They patched our vulnerability. I think it was a ladder. It would be so ignorant to assume that myself is able to find access into the largest dynamics of networks in the U.S. that other countries that have 24/7 hacking teams way more specialized than I am, way better than I am, with as much money as you could ever imagine meant to compromise our country, that they would not find this before I did. The difference is, they would never report it. They would just abuse it. So the API keys to get into flock, did you find any API keys for sale anywhere online? Personally, no, I have not seen any of that. I thought there was something about, there was like a Russian forum online where people were selling API keys to flock. So that was selling access. I'm not sure if it was API keys. Oh, it was just access. I've had so Ben Jordan talked about this, and I remember because he reached out to me asking me about it when we first met, I was like, yeah, no, that's a very common thing. People buy access to systems on certain Russian forums, many of the dark, dark net market forums, the U.S. have been shut down, but you could buy access to flock systems on Russian forums because they don't enforce two factor authentication. So you don't have to really care. You just need a username password, and then spoof, spoof the browser agent. There's no two factor on flock. There is, but it's not required. Imagine, imagine the quick question. If you're someone who's worried about their address, phone number, or personal information getting leaked online, did you know that you can poison your own data? So if you're a company executive, a politician, a celebrity, or another high-risk person, you're going to want to check out Nexonet. Nexonet is Joshua Michael's company, the guests we're speaking with right now, and it's a privacy and intelligence firm. They help identify bad actors trying to get at your personal data. They scrub your exposure to make it harder to find you online, and if you ever are stuck in a court case, they offer litigation support. So if you're someone whose privacy could genuinely put you in your family at risk, be sure to go to JackNeil.com/nexonet, or you can scan the QR code on screen. And for those of you that aren't the ultra-wealthy or celebrities, that doesn't mean that you don't need privacy as well. The same team that built Nexonet also offers a service called Data Minimal for everyday people. They scrub your digital footprint from data brokers, facial recognition databases, data breaches, and job boards. So if you're an everyday person that wants to take control of your privacy, just go to JackNeil.com/data, or you can scan the QR code on screen. But anyway guys, back to the podcast. Just to clarify too, I'd ask you this off-camera, but if I'm a police officer in a county that has flock cameras set up, and we have access to this flock system, am I able to just see the cameras and the flock Nova data for the people within the county or the cameras in the county, or am I able to access something in North Idaho, perhaps? You're able to do a lot more. So it's not just your little local municipality. Like I said, they're able to share nationwide. So you're able to share it with the police people, one department over, one city over. But many of them also just allow anybody to join in, any other police departments, which is where the dangerous capabilities come from. So you could be in LA and you could be searching up somewhere in Florida using their police cameras. They pretty much, this is the marketable reason for flock, a nationwide dynamic surveillance network that you could search everywhere. And so they even have auto, like, exception, auto accepting and auto discovery features. So you don't even have to click accept somebody else could just join your network. I know as some places get more scrutinized, they're starting to limit who's able to access the cameras. I think this is a big issue with ice, a while back, where police officers were doing searches on behalf of ice agents and certain cities were not very happy about that, right? They were using the information to deport people. I want to ask, like, what was the most interesting or disturbing thing you found when you hacked into flock system? What do you mean? I guess, did you find anything in the system that a typical police officer doesn't have access to or what were you surprised that wasn't maybe in the patent or in articles online? Yeah, I would probably go to jail for talking about this for sure. Yeah, so that third exploit I told you about the third vulnerability. What I ended up doing that December 14 was for national security pulled every single device location from their database and never told them about it. This is a test because they had said they'd never been hacked to see if they could detect it, to see if somebody has hacked them and they would know it because I'm a substitute researcher. They would reach out to me at least once if they saw that I did this knowing it's me.
So I pulled the device location, every single device nationwide, even the one in Africa. I think three or four times, millions of data points exported. I never told them about it. And then since then, three times they have said they've never been hacked. And this really is where the national security concern comes out. Because I pulled these and I wasn't trying to hide it at all. I mean, I made millions of requests in a matter of minutes to December 14th. So it leaves us with two things. One, flock knew that I pulled the data from this system. They probably started saying that they've never been hacked. No cloud platform has ever been breached, no customer data has ever been breached. Three times since then, January, March, I think June or July. And they pretty much ignored it. I did it, but just didn't talk about it publicly for marketing or a much more grave, serious issue is that I hacked them to December 14th, pulled every single device location and they were unable to detect it and sit there boasting about it ignorantly how their systems have never been hacked. And why this matters is it goes back to that first API key that access to everything the 20 billion monthly reads of their license plate readers locations from every single officer just about from those 5,000 police departments. They built it to track anybody throughout the United States with their vehicle, their likeness, their people. If they didn't know that I exalt rated that data, bragged about it publicly three times that they've never been hacked, they would have no idea if a foreign intelligence agency or other country compromised the heartbeat of our nation to the API key that I disclosed. And so their cybersecurity support, they have became a national security threat. And so when you ask me if there's anything I've seen that maybe policemen don't know, I won't say that I have, but I'll say with those devices, I've seen how poor the cyber security is, that they're prioritizing as a venture capital back from a quarter to quarter profit over the security of our nation. I mean these cameras are everywhere Jack, even with the wing gateways I was talking about earlier. They have them inside jails. They have them inside prison showers. They're looking to start doing weapons detections and all sorts of things. I don't know. I don't know how they were reacting. They see the cameras inside sexual assault and abuse buildings and inside schools looking at wrestling rooms and locker rooms and girls' bathrooms. I don't know how they react when they realize that these cameras are inside prisons and prison showers. I don't know how they will react if a flock didn't know that I compromised that system. Because what does that mean for every single person that was in the system? I pulled that data set. I didn't tell anybody about it. And I started doing my research study. So that people can know about it. A reachability analysis of these cameras, their field of view, and of what people are able to travel to and from work without being detected by these cameras. But being who I am and running a private intelligence firm and thinking about national security and knowing that when I release this it is more than likely going to send me to jail. It has to have an impact that people care about. And so I did these reachability analysis for 22 different sites. Most are military installations. Others are defense contractors of individuals that may live off a military base. So whether it's going to be generals or it's going to be just officers or it's going to be whatever. Most people on a military base, they commute to work. They don't live on a military base unless you're lower level. They will live off base. And from those 22 sites, there is an astoundingly low rate of people that are unable to make it to work. Make it to these gates on the military bases without being tracked by the cameras. In fact, if you want to go to the FBI headquarters in Washington DC, which is one extra one I did for fun, you cannot get there without being tracked by camera. Regardless of the starting point. So I think it was eggland was like 8% of people commuting from a 20 mile radius would be able to make it onto the base without being detected. For the FBI headquarters was 0% whether it's five miles or 20 miles. And it starts to get really finicky when you think about that. I mean, I did Coronado. Coronado is where the seals train out here. And I think San Diego. And so from an intelligence perspective, what does this mean? Okay, well, maybe 10% of people are able to make it to this military base without being detected. But what about the other 90% what if you're able to infer intelligence from this? You are a navy seal and you disappear for four days. Well, that is intelligence in itself. Where did you go? What are you doing? You don't need to spend a year getting pretty much a background check on every detail your life. All your finances, a polygraph test to have the topsy clearance to know what's going on. You just need access to these cameras and the ability to see who disappears when and who are they associated with it disappears at the same time. So maybe this navy seal or all of that team disappeared for four days. Well, maybe they're on a training mission. Well, why is the French translator that has typically attached this special forces unit gone at the same time, same four day period we haven't seen their car on the road? Well, that just means they're probably in the Sahel region of Africa doing a special operations mission and they need the translator, which is very likely today, by the way, this hell region of Africa is hot. You don't need top secret clearance to know when top secret things are happening. That was the point of this study. A way to visualize it and explain to people in laymen terms how dangerous it is. I mean, when we killed the Iranian leader, this is essentially what they did. They compromised the traffic network in Iran to be able to track where he was in real time and know when to bomb his house. I mean, the US and Britain, I believe, even did this exact same thing not to bomb them, but against the Israelis in the past to see when they're doing mission tests. As far as your story, Joshua, you've been doing cybersecurity for the past decade and have mastered privacy, digital safety, making people disappear. Why did you start posting on social media? As a really personal and great question. It's funny because that Ben Jordan video, my face is blurred out and blackened out in the actual video. And I was telling people about it and telling them about all my research on flock safety that they're a $900 million VC-backed company evaluated at eight something billion dollars. And you start to realize they will never acknowledge me right because it causes a lot of financial damage that the company is quantitatively assigned risk for publicity. I realized that I was going to cost this company millions of dollars if I started going public with my research, which I did, but I did it anonymously for a company that is focusing on quarter quarter profits while completely alienating your fourth-minute rides of every American. What do you think they would do to somebody that causes damage to those profits? So I started social media so that I did not get killed. It was to hedge my risk against being killed because this is a $8 billion company who's built the backing of its monetary value off of violating every American's fourth-minute rides. And so I was anonymous in that Ben Jordan video, told my friends about some of the scenarios. In the first time I told somebody that they said, "Oh, you know, Josh, they're going to give you a position, directive, cybersecurity, $500,000 a year. You won't do anything." And then here at the bottom I'll say, like, "Sign here or you die." And I laughed the first time and I heard something similar a second time. I was like, "Oh shit, that's not nearly as funny this time." And then I
you know, shrugged it off, and the third time I had a really close friend of mine, his name is Dr. John Padfield. One of the most honorable men that I know. I explained this to him in depth, and at the end of our call, he said, "Josh, you know, are you physically safe?" And I laughed. I was like, "Yeah, you know, I've got a gun. I stay home." I said, "You're myself. Why do you ask? Well, if you want to come stay with me." Um, to be safer, let me know. And that is, that's when I realized that hiding was not going to be a good solution. I didn't want to be just the random face that disappeared, the random name. And so I started social media, as much as I hate it as a privacy guy. I started social media so I didn't get killed. Are you still worried? Not in the way that people would think, "No, not at all." I mean, the brevity of my risk is nothing compared to what every citizen stands to gain. And so if I'm the only person that could do this today, and then I have to do it, it'd be unpatriotic not to, regardless of the risk. You know, I'd had Andy Boost-Monte on this podcast, I think it was a year and a half ago. He'll be the next guest after this as well. But he explained to me this concept of former intelligence people being signed on to public or privately held companies as kind of a workaround to get around like some government restrictions, specifically around like YouTube, Instagram, Facebook, etc. And in layman terms, essentially XEIA officers working at YouTube to make sure there's no terrorist on YouTube. But when it comes to flock, would you think that they would have a similar setup? Like, is it publicly announced that they have any former director of the NSA or like people on their board or anyone working at the company? No, I'm not aware of any direct intelligence ties, but I've also not researched it. I'm pretty sure the company is backed and partial by Peter Till, which take that as you do. Which I would say is an intelligent operator myself, but that is for a whole different topic. No, I don't think they have any direct correlation with intelligence, but I would not be surprised if intelligence operators have access to it. Because what's interesting to me is that like there's misaligned incentives with a company that has investors wants to increase their revenue every month and has a leakage like this happen because they are disincentivized to want to email you back in the first place because it just loses the money. They just want to like hide it, fix it quietly, etc. You know, barely even fixed it to be candid. You think it's still a risk? The dev subdomains, I'm pretty sure, still least most of the source code. I know the authentication issues, the first API key and the third, they ameliorated. Like why isn't this like a government initiative? Like why is it a privately held company? Because it's illegal for the government to do it. There's a violation of your fourth amendment right of no unethical searches and seizures. But what the government cannot do, it would just pay private companies to do on its behalf. And from your understanding, is there even a question to ask here about that this type of data of vulnerabilities that API, vulnerability specifically, was intentional? You've almost seen that way, wouldn't it? You know, they actually have Chinese investors as well. I cannot see a company. There's worth so much money with the most arrogant CEO I've ever seen. Doing something like this, unless it was intentional. How do you make that mistake 53 times? Access to the entirety of our country. I don't know. You know, it's an inquisitive thing to think about. But I would not be blown away if it was intentional. But for what? Why not just give access to wherever you want to have it? Unless there's something more subtle going on behind the scenes. I would not know the downfall of our country. Our flock cameras in other countries, you said Africa. Yeah, inside the Africa. There also, that means none of the country but down Puerto Rico as well. But that's the only places. The Virgin Islands. Got it. It's mostly the US territories. Oh, yeah, for now. In regards to privacy, flock, or digital security. Like, what's the one thing about all this that you haven't said out loud or online? I never shared that I hacked the company and never told them about it. Oh, that's not on your Instagram. Yeah, no. Because, right, this is such a large issue. The entirety point of my study. And they will refuse to acknowledge the risk that they opened up by the vulnerabilities I found. This is me essentially saying, I have your entire database. And you are going to have to acknowledge this for our country. And I'm going to publicly share all of it. Every camera location, every device location. Every single piece of research that I've pulled over the past year. It will be going public. What are you sharing it? Shortly after this. So, this is why I tell you, I'll probably be in jail for it. But not sharing it would be the least patriotic thing I could imagine. You're going to go to jail for sharing this. This is a ethically gray area. And so, the computer fraud and abuse act is purposely non-verbose for this exact reason. So, there's many arguments that it could be made. And I won't get on to them on this podcast. But yeah, I could be arrested and go to jail for this. I genuinely believe I will be. I'm not sure if you're familiar with the work of Professor Zhang online. But he's known for making a series of predictions like Trump's presidential election. The Iran War starting and he'd also said that we would send ground troops. But one prediction he'd said to me on my podcast was he was something like by the year 2060. We would have a total AI surveillance state. Do you think that's the case right now? We're already in there. Yeah. That's what these cameras are, Jack. They are an AI surveillance state. People, animals. I told you when they add in audio, the ability of public utterance will be lost. Freedom of speech will be curved. This is how you slip into soft authoritarianism, whether I would explain it. I don't know any individual that wants these cameras. Or very few, I'll say that much. We're in a time where America is not worth it. We're not being represented by our politicians. You know, the government is supposed to have its power from deriving the consent of the government. And yet today it has never felt so far away as we are being exploited and taken advantage of. Where men like you and I are so far away from the American dream. Now we have the opportunity to work for the next 20 years for the chance in a middle class house that used to be affordable. Because politicians are feeding themselves, treasoning our country, treasoning Americans for their own gluttony and greed and money and power. They are meant to be public servants. We are meant to know everything about them, and they are meant to know nothing about us. And yet it's not like that. In fact, they are privacy laws that me and you did not have. You cannot sell the data of a sender of any politician. It's illegal. They are cognizant of the issue. But they won't extend it to me and you, to Americans. It's illegal to sell the data of a congressman. Yeah, of politician. Yeah, this is the most disgusting form of greed, though, where it's so blatantly in front of us. I think within the next five years we will have a massive change in this country. Men, women, my age, your age, a little bit older. Our goal is to start moving into political power. And these people are not doing it out of greed. They will do it to restore America to what we were found to pop. You can only lie to people for so long without change happening and to be candid. What has happened every time in history with a bunch of 20-year-old men are unable to afford food, unable to abort a house, unable to get a job, and are doing nothing except sitting there. A coalition that starts every single time of young angry men. And this is only going to be amplified by so.
the social media today, I think within the next five years we will have a massive change. And if not, then within 20, we will be much closer allies with Russia and China than we will be with the NATO and EU countries. So his prediction of 60 years, AI authoritarian surveillance state, it's the path we have to move away from today, or we will find ourselves there. And then to the everyday person who's just, who's maybe not as concerned about a national security threat as they are about their own lives, like from what you've read or seen online, what's the most disturbing thing that flock cameras have been used for that you can say? Tracking people that are having abortions, buying marijuana, things that may not be illegal in their state, is there one story that stuck out to you? No, to be honest, there's so many that honestly my brain has become desensitized to them. I'm the first one though. It was a lady was falsely identified with her license plate, and they forced her onto the ground with her children with her guns out. All because you're a license plate reader made a mistake, you've traumatized these children. What kind of public safety is that? This woman and her kids had to lay face down on the eye asphalt in their hot summer day with guns pointed to them because she drove past a camera in our free country. I remember I have had access to a lot of things that flocked never once publicly revealed. And one of those seminars, one of their individuals actually talked about tracking people that are doing suspicious things, and I was like, well, that doesn't. Why do you get to deem what is suspicious and who gets to be able to track? And so they talk about people that may drive through multiple jurisdictions up and down the East Coast corridor, showing up in multiple different camera networks without a commercial license or a reason to be driving, as he said, is something they advocated for researching these people. But I don't know who the hell they think they are. I need to call up Garrett Langley and tell him, hey, buddy, I'm going to be driving from Florida to New York. Can you make sure I don't get put on a suspicious hot list? Thanks. Appreciate it. I'll let you know when I come back too. It's like, what in the hell? This is the problem with flock that we don't see with axon and motorola. The government's controls are so horrible. You know, they had the issues with offices abusing the system and putting in the reason field nothing or things that they did not want getting out. So when people start doing freedom of information acts and public records request, they had to change it. And so now it's just a drop down menu. And to put people on a hot list, you don't need a warrant. You don't need a case number. You just have to put a reason for why they're going to be flagged and detected every time they drive past or walk past this camera. I mean, this is police state type shit. What happened to you are innocent until proven guilty? We are now surveilled as if we are guilty and then have to prove our innocence. And so hacking a company after showing I was ethically doing cybersecurity research. Something significantly changed. I saw the national security risk and I deemed it enough to pull those data points. This could change the computer fraud and abuse act. Even when I get arrested, we'll have a good argument. I didn't do this because I wanted fame. I didn't do this because I enjoyed bringing pain or suffering to flock. I did this because I see this as a genuine threat to our American sovereignty. I mean, if I wanted to cause the largest data breach in history, the largest national security threat America has faced in the 21st century. If I was truly malicious, why would I not have done this the first time in the API key, pull the data of every single American caught in these games? Of tens of thousands of police officers. You know how much money I could sell access for that? How much could you sell an API key for for flock to the heartbeat of our nation? Who knows? Millions of dollars. Really? I do not want money. I do not want fame. I want people to be safe, and they're doing the exact opposite of that. If I'm someone that has a car, drive past these flock cameras, I think you said 3.2 times a day on average, like what's the simplest way to get a round flock cameras? Put your car in a trust or an LLC and register it through that. Now you have one separation layer. What does that do exactly? Well, when they pull your license plate, it doesn't show up your name directly. It shows ownership to that trust or LLC, but they are the police, and so they have the data that they want. It will still get broken through. Can you look up anyone's name? On flock Nova? Yes. On flock safety. It's primarily the feeding into flock Nova. The flock safety, you could search up vehicles, people, not names directly, but that's why they started selling flock Nova. And so you could type in some eyes name, the social security number, their phone number, their email, passwords. I mean, they even use hacked and breached data to track and exploit people's identity. Without a warrant, they could tell you just about everything about yourself, and it populates it in sheet maps, and it populates it in activity timelines, and they know when you're most active in certain locations and doing whatever, in flock Nova, you could look up just about anything about somebody. In regards to the work you're doing now, like your actual business, what do you actually do for a living? Well, we hope people digitally disappear. That's the primary thing. And so celebrities, politicians, executives, we're pretty much a white glow service that makes you, your family, and whoever pays, with exceptions, disappear from the internet and from being able to be traced by many normal means. If you think about it, we're in a time where all your information is being sold, and so it is a luxury to be private. The thing with social media, you know, I told you, I started my social media, so I didn't get killed. I found so much joy in helping other people for free. It started cannibalizing an absolute insane amount of my time, replying to people and giving advice through DMs and text messages, that I wanted to expand, and so how could I do what we do at next net for people that aren't executives, politicians, celebrities, and so we built on an application that essentially does a majority of it for you, words, a data broker removal, like you know, and cognitive delete me, these, these great applications, but we take it a step further, removing your image from facial recognition databases, from job and career sites, because if you think about it, your resume is a very detailed list of everything that you've done and your emails and your phone numbers and your name and address. That's an overall insane tool that's meant to take that 4K package that we have baseline from next net and give it to people for $30. This is my opportunity to help change the world, I think, change the United States. And if I could make it free, I wouldn't, but I would just be imaging money the entire time. But I love giving out the advice for free on social media. So touch on some of the ways that people's privacy, security online is compromised. Do you think people are paying different prices for the same items based on the data companies have about them? Like what is surveillance pricing? And more than certainly. Yeah. I mean, look at the app like they're 60. They were caught selling location data, I believe also like the hard breaking data to insurance companies, which ended up jacking up people's rates. I mean, this is done recurrently throughout the United States. I don't know if it's CVS or Walgreens. One of them has emotional intelligence and facial recognition inside their coolers, so they could read what your face is like, read the emotions on it through your micro expression. And if you're happy, you know, to upsell you to more expensive products, or if you're sad then maybe some ice cream or whatever, it may be cheaper products. This is going to happen recurrently. I mean, Uber does it as well, if your phone battery is low. I'm pretty sure they charge you more money than a typical individual would be charged. Surveillance pricing is coming. What if they charge you more money? Well, there's urgency. Your phone's about to die and you need to get somewhere. Oh, shit. Yeah. What are you going to do? Walk. (laughs) - Yeah, Uber.
this sketchy company. In fact, I can't say it was Uber directly, but flock bragged about catching somebody, catching a criminal, which is great by the way. Like I do advocate for the use of catching actual criminals. This is an advertisement flocked over. They used a meal delivery app, a food delivery app, and the location data provided from that, to find out that somebody was not their house, but a acquaintances' house to go and arrest the individual. Hmm, I can't say it's Uber. I think it's Door Dash, wasn't it? Yeah, I'm not surprised. But these companies do not care about your data in the slightest. They don't care about your sovereignty of your data. They just want to be able to settle it. Like why the hell do I need to give you my full name, my date of birth, my email address, my address, to get 20 cents off of apples at a grocery store? To be in your rewards program. This makes no sense, you don't need any of this. You're just going to harvest my data and then sell it to advertise it. But people don't realize how significant that is. Add technology is meant to manipulate your mind. It is meant to change the way you think. I mean, this is where the Cambridge Analytica scandal came from. In fact, I have a friend of mine that, before he did what he did today, was doing political campaign stuff. And so they bought location data and advertising data on individuals and I think in the state of Nevada. To influence an election. Using this same data that you give out to people when you're using these applications and signing up for all these websites and apps. What they did is they found the way that people were going to vote for or against their candidate using that location data. And start running campaigns to make them not go to vote. Because it is easier to dissuade somebody from going out and not voting for their candidate. And it is to convince somebody to vote for somebody they disagree with. You know, it's an identity thing. Isn't that crazy? Add technology being used to sway our elections. Not to go get people represent themselves and vote, but to make people not represent themselves. Not to vote. It's funny. I question a lot of the sentiment that I hear online in one of the big pieces of sentiment is political content is pushed to rage bait you in like spike your emotions. But maybe it's just pushed to gather some data. Do you think there's any truth to that? - Oh, completely. Yeah. I do. Funny enough, I mean, this is something that algorithms found out by themselves. It wasn't human finding. I think I actually learned this on your show. Where they will show you an ad after being shown something that is emotionally engaging. Like I think it was puppies or something. But yeah, this is done recurrently. I mean, if you think about the terminology and the rhetoric of social media today, right? We started calling it social media application, whichever platform you choose, where you're meant to be able to see your friends. Have your social group, DC physically, but digitally, meant to connect you. And yet today we're so cognizantly aware that these platforms push massive propaganda campaigns to have an amazing amount of censorship. You are shown strangers more than you are shown people that you know, often times with malicious intent. It's unique. It reminds me of when we started using radio. And the blessings of radio was propaganda in Vietnam. And with technology today in this short form of media. You could do the exact same thing in a short little emotional clip to change how people think. It's unique rhetoric, too, because it's called social media. But it makes us more anti-social. It makes you deeper, identify with your already set in identity. The rhetoric on that word is crazy. The thing with this short form media is that it gives you the capability of having strong and resonant, ideas, or opinions, but without having any of the actual knowledge to back it, to justify it. And so it creates a very polarized group of people, whether it's over politics or economics or religion, whatever it may be. They give you a bunch of hard-hitting facts for what may seem like facts. But you have no ability to justify it. You identify with it though, and you argue about it, 'cause you cannot be wrong. It gives you an intellectual obesity, what being left with thought poverty, idea poverty. You could argue with me about some of the dumbest things in the world with a scientific expert opinion. You have no idea how you got there or why, other than watching this short form content. It's almost like mind control, because we're actively being taught not to think. 90% of people left or right all want mostly the same thing. You want to have a house, you want to be able to take care of your family, your kids, to be happy, education, a livelihood, to have humanity. But if the 5% of extremists on each side are what's shown the most, they're the most polarizing. But you never see the 90%. Even though only one thing may be in disagreements whether it's going to be whatever topic you choose in politics, most people are humans, and we agree with each other at the end of the day. Social media is not meant to bring you together. Although I wish it was, you called it almost like mind control. Instagram reels YouTube shorts, TikTok, like what's the main objective of those algorithms to change the way you think? Completely. But like in what way? In what direction? Well, it depends on who's doing the propaganda. This is why it's unique in the US. This is the first time we are being put in the crosshairs of narrative intelligence and propaganda from other countries. And we get disinformation campaigns from Russia, trying to divide us on topics. We have massive propaganda campaigns from China and Iran and Israel and just about every country you can imagine. If it was one solidified thing, one message, it wouldn't work. It's drowned out by all the different people playing in the field. But you have to realize that regardless of what the content is, you are consuming it. And you're in an emotionally available and sensitive state when you're sitting there just scrolling. Mm. So there can't be just one thing that's meant to do. But it does make us less social, unfortunately. And it opens us up to propaganda from other countries. If you had to give me maybe the three biggest lies being pushed on social media in 2026, what do you think those would be? I don't know if I've got three, but I know at least one is that you are much more isolated than you can imagine. People sit here and think nobody's backing them. Nobody believes in them. They're kind of sorrow that lonely. But this is just a viewpoint. I mean, if you talk to people, people love other people. We have the collapse of the community. And so people don't realize that what you say, what you think, what your opinions are, are backed, regardless of what topic it is in. You just have to speak about it. You are not as isolated as you think you are. You just don't take the opportunity to let other people show you, they support you. It's a unique scenario we have today, where people are afraid to talk about things. Do you think the male loneliness epidemic is real? I think that's a American epidemic. Everybody does that. Now, most people send their phone and scroll all day and consume this propaganda. And then every other ones in a while get good media. Yeah, I mean, think about this. Think about you have passed away. And you were looking down as a spirit from heaven or whatever you would like to call it. And I'm looking at you and you're here on your phone. Looking at this blank screen of ones and zeros at the end of the day, truth and false, with the entire world around you, and that you sit here and have your head stuck in this device, ignoring reality. I think we're finding addiction in that, which is why there is a loneliness epidemic. People are not going to third places. They're doing less and less hobbies ever than before. Aside from typing in their license plate or getting access to their advertising data, what do you think is the most effective technique to get information out of people? Elicitation, human intelligence. People will leak secrets far longer and far better than systems ever will.
Elicitation is the ability to befriend people, make them like you, and put thoughts in their head that you are steering so that they tell you things that you want to hear, that they may not necessarily talk about. I mean, it's also a way to change how people think, to change their opinions. Are you interested in elicitation, human intelligence? Yeah, I'm super interested. Yeah. Yeah. Some people have it naturally, and some people have to train for it. I give you the newest terminology today. It's called rascals. Have you heard of this? So if you want to compromise somebody, the intelligence community would call an acronym MICE. So it's like money, ideology, compromise or coercion, or ego. And so these are reasons why people would do things that they may not necessarily want to do or agree with. But actually building that connection, getting people to compromise, comes through using rascals, which is reciprocation, authority, scarcity, commitment, like ability. The last one is social status. If I wanted to elicit information out of somebody in the most efficient way, I would just mirror them and befriend them. And then start making them think that small ideas that are my own are theirs. And so I would mirror you just like this and sit. And then I would shift the conversations towards something and put two things right next to each other without actually saying it explicitly. So when your brain puts them together, it will think it was your idea. And it starts off small. You change how somebody's identity is to their own thoughts. Seems pretty effective. I've met people that you cannot imagine how smooth they are when it comes to infiltrating your mind and your mannerisms. What's one technique those people have taught you? I wouldn't say they taught me anything, but they, something you observed of the mirroring is flawless. And also pretext. They start talking about something that they know they want to elicit out of you. So you put a relationship, I sit here and I mirror everything you do. And I start telling you maybe about my personal life or my childhood or this or that, knowing that after I ran down for five minutes, you'll either interject sometime and tell me a little bit about yourself or when I finish, you'll start telling me about everything that you can mirror in that situation. So I'm leading you into expressing your ideas, the things that you may not usually talk about. And they're very, very good at that. It is not business, it is a friendship, it's just a very well crafted friendship. You have to become blood warm with people. How can you tell someone is lying to you? Sometimes I say intuition, but I think that's just an easy way to say their baseline is moving. You can't do this immediately, but you could tell if somebody is normally acting in one certain way. And then you probe a question or a topic and you see them start blinking fast or they're sweating, they change the words they use. You have to know somebody from a baseline, which you can get fairly quickly. And then you're able to tell if they're going to be lying to you just through the micro-expression so they use. You've used maybe in our conversations or videos you've made online, like the terminology, what is it? Human, a signet, an austenite, I believe? Ocent, human, geoent, the signet, there's a million different intelligence, narrative intelligence. I don't think there's an acronym for that. What is all that used for? And which one is kind of the most important type of intelligence collecting in today's world? Yes. Depends on your goal. I mean, geospatial intelligence is important when you need to know what things are and what they're doing. Human intelligence has almost always been the king of all intelligence though. Like I said earlier, people will leak secrets far sooner than systems will. And once you compromise an individual, they can be compromised for a lot longer time. I think that's an issue that we have in the United States today. So many people are compromised. They could not do things that they necessarily may want to, especially in politics. It's humans. I'm kind of shocked that people don't train more around human intelligence because it would improve everybody's life. The ability to talk to individuals, to talk to people, to express yourself, to have confidence. It's funny because half of human intelligence and what could be nasty about it all comes because it makes you a better socializing. You need to make people feel better of all the various intelligence agencies around the world. Do you think massage agents are the best spots as human intelligence? Yeah. As human, for sure. Why? Well, this is what they were practically trained to do since World War II. I mean, how do you think Israel came to be? How do you think they became so good at human intelligence? So during World War II, say, we want intelligence on Germany. We want intelligence on the Italians, which Germany is taking place of. What is a better group of people than Jews that are Germans, they were born in Germany, they speak German, they have all the cultures of Germany, same thing with Italy. What is better than using people that are natively German and Italian that disagree with or are being persecuted by to get intelligence. And so they became spies in their own regard, Italy, Germany, France, by nature, out of necessity and Jews at that time period were essentially intelligence officers operating using human intelligence. And then when you have a country where everybody goes back to Israel, what do you expect when half of the people coming back for spying for the United States during World War II? And they've done this for longer than the United States has, was besought the first intelligence agency. I wouldn't say they were the first, I don't think so. But they were before CIA, right? They were. But we beat them at pretty much all other intelligence. I mean, you would not believe the kind of things that U.S. military could do. Oh Lord, but the human intelligence factor is the scariest because it's people that you meet and exploit your humanity. Not data. I don't know if you're able to talk about this too much, but in regard to the Epstein files, what's the most interesting thing you learned about that case? And well, I can't publicly talk about that. That's the thing that styles me from getting killed. The people are alive today that we know about, we're a private intelligence firm first, that we could expose correlations and connections to Epstein and Gazane and the entire group. And so that's actually where some of my safety comes in. Because I plan to stay alive for as long as possible and, you know, messing with a 900 million dollar company or releasing information about Epstein is, or they're associates, puts you in a precarious scenario. And so as much as I would love to share that with you and with the world, you only go out if I die because if I die, and there's no reason to hold on to it, but they would be often the same man of the, publicly in terms of Epstein and the entire scenario around him. I think the most disgusting thing was how people just have just accepted it. We are so sickened by it. We are sickened to death by everything that happened. They feed you small little details over and over and over again. So when you get to the big reveal, you've already become desensitized. You don't think it's crazy that we have panels as a ruling class in the country that is supposed to derive the government from the consent of the government. And there's nothing you can do about it. This is why I talk about politics because it's so overwhelmingly apparent today that things have to change. It is not a massive change that has to even be taken place. People talk about tearing down these flawed cameras. They talk about revolution and having to abdicate the entire sovereignty of what we are today is never, never good to use or a good word to use revolution is horrible rhetoric. And it would be untrue, revolution covers the idea of violence, of killing people in justices, being solved.
It would be closer today to a restoration, which should never be violent, but we have to restore power in this country, back to Americans that love Americans. They want to ameliorate the issues of this generation, the next generation of people loving, problem ameliorating individuals that care for humanity as a whole. And so when you think about it that way, I think that is the only thing you should take away from the Epstein files that change needs to be made politically through government, through juries and trials and arresting individuals that have treasoned our country in their own selfish desires. If you have sold out our country for money, do you know what you get charged with and what happens to you if you found guilty of treason? You are killed. You can be given the death penalty. If you've sold out our country for money, or you sold out our country for anything, you should be tried in a court of law. And if ultimately found guilty, we sold out every American citizen for money. You agreed. The last thing you should feel is money beneath your feet when it gets kicked away and you did that. That is what a restoration is. Using government and law back to the United States of America, back to citizenship. Something you said there that was really fascinating was that the details and the files themselves were released in such a way that by the time we'd had three million documents, no one cared enough to start some type of revolution. People weren't in the streets. Despite people being in the streets for something like the No Kings protest or the death of George Floyd. And what I find interesting about that is do you think the Epstein files had malware on them? Maybe something to I talked about. It would have been the most genius way of trade craft to compromise, you know, people that care about the Epstein files to classify a group of individuals that may be a risk for this case, for the scenario that happened. Journalist, it would be so genius. In the NSA, you could do things you could not imagine. I just think it's unique, though, because three million files. And what the hell is going on here? The FBI is supposed to be representing us. We pay for them to do these investigations into crimes, federal crimes. And then they drop three million files and then tell us to search through this good luck. We're not going to actually charge anybody. We're not going to do anything. You have to do the investigations. What is the point of the FBI if they're handing the investigation to the citizens of the country? I mean, I see them as a necessity, but they must clean this up. I don't know what the point is today. It's like every single thing in the US is not serving the American people. What do you think it serves? Money. Money in power. And in a pseudo-capitalist country, and it's forth-turning, money is worth more than you or me or anybody. Did you do any research into Palantir? Yeah. Is that connected with Fox Safety in any way, aside from the investor? I wouldn't be surprised at all. Well, you have the pita teal things, obviously, a unique connection. But Palantir is essentially a massive data silo. For people that don't know, they're a data analytics company that allows you to put all sorts of different homogeneous, heterogeneous different types of data into one place. It's searchable to make it easy to see the sea patterns. So it's similar to flaknova? No, no, it takes all data. Like every single data identify you to magic, not just for people. I like transactions or analytics for website clickters. It takes everything. It's meant to say every single aspect of your business, whether it's digital or it's in person or it's just anything. It can go in here and it'll be usable and you can search it and you do whatever the heck you want. There's things called fusion centers. You can get to them like a company called Paragrad and they put data together the same way that Palantir does. A lot of police departments use Paragrad now. I think it has to do with the flock safety, freedom of information, etc. where people are pretty much saying, show me if you've ever searched my record or my license plate and have to hand it over and the police and Garrett Langley will be very mad about that. So if you don't do that search in flock, you buy this accesses company called Paragrad and they're Palantir light much cheaper recently and then you do that search in Paragrad which is a customer of Palantir and we put it all together. The data starts flowing up, doesn't it? But to be candid they don't even have to do that. I mean they do illegal stuff all the time. Look at the wiretap stuff that Snowden talked about. The NSA was doing it illegally regardless. You know it was really scary. I put out that list on the website of I think 600 companies that are working with Palantir sending their data to them. I mean they're being used for killchains and war. They use for practically everything in the United States. Most companies you worked with or use have been sending data to that company for their own reason. A data siler like that, all it takes is a second Patriot Act and you have everything about everybody in one company. In fact, I remember that the Department of War put out a memo for their AI use case and how they're going to be AI first and they start slashing a bunch of compliance controls and governance controls. Talk about we are acting as if we are in war. If you want to reject sending data you have to give us like a five days notice and the reason why or some crap like that. I asked Tucker Carlson about this and we did a podcast together. It was something along the lines of I read an article or piece of writing from this journalist Whitney Webb. Have you seen her work? Whitney Webb, not recognize the name from. She can't remember what the big story was that she released. Maybe it was something around COVID or the Epstein files themselves. But she had this claim that Palantir was like the new Jeffrey Epstein in regards to the types of compromised data blackmail they have on this network of politicians based on what you know about. Flock safety, Palantir, this other company that you mentioned. Is there any credence to that? Knowledge is power, data is power who holds it all. Of course you do not need Epstein if you're able to do and compromise people through systems. I mean think about it from just a flock perspective. You find out that a politician on a Thursday night went to an apartment complex that he's never been to before. It's just becoming a routine. What are you doing in this apartment complex? Why is your wife not in the car? Why are your kids there? Why do you leave, disheveled? Hey, you got caught on a license plate read about it. Hopefully nobody ever uses that against you or it expands to their wife or their husband if it's a female politician or their kids. This is the thing when you track everybody doing practically everything. You become blackmailable. Whatever controls the system holds the power. Is my car spying on me? Well, yeah. What kind of car do you have? Do you more specifically? Jeep. Is it newer or older? Nure. Yeah. Anything that all those chips and Wi-Fi enablement, they're spying on you. Do you have like on-store? You know what that is? Yeah. How does it know where you're at? Where does it know your location? Everything is technology today. You know, when me and you were growing up, technology in the internet used to just be a room in the house with a computer and that computer was the one gateway to the world. But now everything is a computer. Everything has technology connecting to it. Even your car, even these sensors on your car, like your tire pressure sensors, our little computers sending data back.
Of course, it's buying on you. I mean, look at SignalTrace. SignalTrace is a company, or it's an application from a company called Leonardo, and they create what they call our fingerprints. Same way, flux agent does vehicle fingerprints. They do it for identifiers, and so NFC, which is going to be the close contact stuff you have on your access badges or cards for Bluetooth identifiers for Wi-Fi signals, they're putting these around the United States, and not only just on highways, but also on subways and other areas, to sniff out the Bluetooth and Wi-Fi identifiers that are coming from your vehicle, and from your phone, and maybe the Bluetooth headphones you carry with you, so you no longer have to know that this is the car, this is the registrant, we can know everybody who's in the car based off the unique fingerprint by the devices they carry with them. I mean, your car is spying on you, per se, but this is a part of what the internet is today in the Hungryness for Data. I think GM, I don't know if it was GM or who, they got caught selling data to insurance companies about the locations of their customers. Some company, I think it was Kia. I can't be certain though. One of them even tracks your immigration status. I don't know why the hell they need that, but oh, your Jeep is more than likely sending out data that you're not even aware of though. If I have a phone, and there's a flock safety camera, I walk past it, signal trace Bluetooth to my phone, they get access to all the advertising data they have. If I walk past a flock camera with my phone, can they get any data of things I've said to my phone? Does that make sense? If Snapchat sells the recording data, do they capture that kind of data? No, I don't think that is necessarily a risk. Also, signal trace is not by default on flock cameras. They're different products. The things you say to your phone, not so much, no, unless it's coming with like a warrant, even though they don't need it. But you have to request that data specifically from the company that you want it from, so whether it's Snapchat or Google or whichever one. As of today, I don't think it is a massive risk. Again, I think it comes from the devices you don't own when flock safety cameras start recording audio. Well, they don't need to go to Snapchat. You talked while you walked past them. Even things like we have to have controls in place to stop this, because otherwise every single aspect of your life will be detailed and scrutinized and judged by systems that have no humanity. You'll be judged by systems that are not even human and being left to prove your assets after being found guilty. I mean, does that concern you the long term effects of this type of technology? I mean, do you think that AI is going to kill us all? I would, well, there's two different things there. You know, I do think AI will probably be the ending. Someday somebody will make a mistake and give whether it's AGI or ASI, so artificial general intelligence or artificial superintelligence, I don't even know if whoever makes it there. You don't even need to be candid. They're going to give AI access to a system or a weapon without a human layer control. And before you know it, just takes one mistake. For it to have access to a system, they can send a new counter, send a bomb or do whatever the heck it may be, that access control layer will probably be the last thing that saves humanity. I mean, we see it today with AI hacking as companies and such, escaping their boundaries. I mean, military is integrating AI heavily. The only thing most of the time stopping missiles from being sent out is that one layer of human review. What if there's a mistake, somebody doesn't have that, and then you get into the poisoning aspect. They ingest so much data to train these models. What if it was poison, almost like a sleeper agent? You put in exact code all over the place across the network to be scraped and it's trained that if you ever see this phrase or this string of text, something that you, you were I would never notice, it gets trained into the model to do something that it's not meant to do. And then they send an email to your computer to your email. Maybe it sees that code in there, the sleeper agent thing, and it does whatever malicious act it was accidentally trained on. That would be interesting. I don't know if many people think about that scenario. That's interesting. Do you think there's, is there any private company you suspect that does something along the lines of gathering, and we've already described it in this interview, but individual profiles based on people, I kind of like a social credit system thing? Didn't they find out that some company was just doing that? I don't remember, but I think it was some company was taking into account like the phone battery, how often you charge your battery, and if it's low or high, or if it dies or whatever, and as a part of their online credit rating for a hiring process. I don't know where the heck I saw this, and I may just be making up, but the social credit thing is, I mean real, I mean, look at the credit scores that we have today. Look at the profiles that you have for your advertising. Look at the stuff that's sitting up for predictive policing. You have a bunch of different profiles about you that you may not even be aware of. What the hell is predictive policing? You don't know about predictive policing. The likelihood that you are going to commit a crime based off the information they know about you, and maybe your genetics or your family, or your family lineage. And do you think they're buying that advertiser data as well? Well, of course. They got to know more to be able to predictably police you, and know your likelihood of committing a crime to target you before anything ever happens, I suppose. Yeah, it's national security. Just actually like the tip of the iceberg, though. Oh, yeah. Then you get into like genuine monsters, like Lexus Nexus, or Experian. The actual credit brokers, the TLO companies, where your credit score comes from, they're like a digital colonoscopy. And there's not a, you really can't delete much data off of it. Because when you do, or if you try to, it's going to mess up finances. Right. The technology in general, I, do you think people should use Face ID to unlock their phone? If you're a normal, everyday person, yeah, I don't see a massive problem with it. The thing is your phone is relatively secure if you have an iPhone or Android, which everyone you want to use, and it says it stays local, which I haven't done any personal research to prove that it does stay local, but I would take that to a degree. The only thing that gets sketchy with Face ID is that if you are ever detained, or maybe you're going through border patrol or customs or whatever, they cannot make you hand over your password to open your device, which is your, your life in a way. All the people you've talked to, I mean, imagine getting access to somebody's email or all their photos, but they could do that with fingerprints and Face ID. I recommend people using it if they're just a normal, everyday individual, but if you're going to travel, turn it off. And so you're not forced to open the device to give over your life. Otherwise, who knows, who knows what they may deem to be wrong or reject you from traveling for? Right. How long is your passcode on your phone? It's huge. It's like 40-something characters. Do you use Face ID? I do. Huh. I keep my phone on. I have a couple of phones, but I use Face ID on one of them. The other one is just long passcodes in the phone, auto resets every few hours. Where's the safest place to actually store your passwords on your computer? Using something like key pass xc. But again, this is on your device. It's locally hosted. And so it's a little bit more of a pain in the butt, so then maybe you can't pull it from pull your passwords on your phone because it's on your computer. But there's great middle ground. Like if you were not some extreme threat model individual, why not use something like a Bitwit.
or proton-pass, these open source alternatives that are public, that you're able to have across multiple devices. This is one of the things that I suggest for our clients. At first, is "lie" on the internet, which people don't do enough of, by the way. And two, is just start making these small privacy switches. The change is how much data you put out, how much data exhaust you have, significantly. Why should you lie on the internet? Do you remember the time of my space, and where they say, "Don't even put a picture of yourself on the internet"? Don't put out your name. Technology has changed so much. We went from never give out your information to strangers, to give out your information to everybody, and your social security number, and every picture, and every place you go. Again, when you were giving out this information, more often than not, it's just being used maliciously against you. Why tell the truth? Why do they need to know that this is Jack Neal signing up for gas station rewards credits? And it comes back to data breaches. This is the one thing that we work the hardest to try and fix for our clients. Because once a company has hacked, once data has been breached, every identifier in there that has been compromised is there for eternity. They end up on a dozen breach websites, and whoever has that database locally will have it. And, like the flock devices, I will permanently have every location point for these flock devices stuck in time December 14, 2025. And these identifiers are how we track people. It's like a social graph. In fact, I told you about the individual I was friends with in the home that was really high ranking in a couple different agencies, and the one there in the home. And he essentially told me over bottle of wine drinking a little bit too much, that most crimes are solved through the data exhaust and advertising IDs. And, through breaches, in terms of privacy and security, you don't realize how significant just one data point is. Your name, by Google it, can send me back to your age, or maybe your wife, or your husband, or your children, or your address, and that one data point extrapolates into dozens of things. And then, you start looking through breaches, because companies get hacked all the time. Anything that is online can be hacked. And now, I have a connection to your credit card, or your social security number, or your passwords, and you reuse that password. So now, I start using that password as a key to search across data breaches, across maybe accounts, or whatever it may be. I start uncovering hidden details about your life that you tried to hide. Yeah, maybe you have a second email that you hid, but use the same password. Let's see what accounts are connected to that, or even IP addresses, even though they rotate, can be damning at times. You got to lie on the internet. There's no point in giving away more information that you gain nothing from. Do you think VPNs are scam? Not a shot. No. Most VPNs are scam. They sell you guys of security because of your own ignorance. But this is really good. I mean, look at Mulvad. Mulvad is a superb option, by the way. I mean, you could even pay with cash. They take no logs. Everything runs and RAM. You don't give any identifiers, no email, nothing. And so when you use it, nothing is traceable back to you from that VPN. Proton is also extremely good. I like suggesting proton, right? Because it's a whole suite of privacy products. You own the encryption. You own the encryption keys on your device, actually, partially. It's these small little changes that people make that end up giving you back your sovereignty. With a VPN, I said earlier that they cannot find you with it. This is partially true. You know, your IP address will be masked. Your DNS will be masked. But if you log in using, say, Google and you have an account and you've used these credentials, obviously, it would just show that account, which is you, but from a different IP address. But for a majority of things you do on your computer, use a VPN. But not the ones that are marketing agencies pretending to be VPNs. Right. They just sell you data. Pressure Facebook has a VPN. Can you imagine using that? Apple has one, I think. Oh, the iCloud relay. Yeah, they're decent, okay. They're decent as well. For lower threat model on data breaches. You're making me think that maybe data breaches aren't done by like anonymous hacker groups. No, no, usually not. It's split up into like a handful of categories, I suppose. They usually young men about my age, your age, down to like 16, and they're doing it for ego, for money, for fame. That's like the scattered spiders group. And then there's what we call APTs, so advanced persistent threats. And these are nation states that hack for countries. And the ones that APTs do, right, they don't usually disclose breaches. They keep them for their own intelligence. But the independent groups almost always do. I mean, look back at the Canva breach. You remember this? 270 million people. That's a lot of data globally done by a group of kids. It's funny because it goes back to that human intelligence we were talking about earlier. Data breaches used to be, you know, SQL exploitations or using eye doors or indirect object references to pull information from systems that you weren't supposed to have access to. But today, it's primarily social engineering. By kids calling up help desk lines pretending to be an executive or pretending to be a support member, whatever it may be, and tricking these people into giving them access. It's like huge. The scattered spiders group is known for their social engineering. It's how most data breaches happen today. They give away the access themselves. Because some kid was very convincing online over the phone. I want to touch on something you said a second ago. You said that a friend that you'd had over one had said something along the lines at most. A high profile criminals were caught via their advertising data. Was that the most criminals I got through data exhaust or data exhaust? And so all the data that you put out in your everyday life. I mean, you carry your phone around. The geolocation from the cell towers is data exhaust. If you log into a website, the IP address, the geolocation points, the people that you have on there are all data exhaust. Data exhaust is everything that you do. From emitting data from your devices. And yeah, advertising is a massive portion of that as well. So when you look at something like this Charlie Kirk loan shooter assassination case, where Tyler Robinson was the person said to be the kid who shot Charlie, I think he was 22, and he's on trial right now. Like are lawyers in the judicial system considering that data? I think it'd be crazy for them not to. How is it even a question of who fired the shot then if the phone tracks everything? Aren't they blocking portions of that investigation as well? I don't know. Sometimes it is all just political theater. I sit here and I genuinely consider that if you wanted to commit a crime, you will be caught. There is this much general surveillance, not targeted surveillance, general surveillance, and expectation of you doing anything. You were surveilled as if you were already a criminal. But this is the same thing that happens happened with 9/11 where these agencies were just selfish and did not share data with each other. The data is all there. Sometimes they just do not want to solve the crime. I mean, genuinely, think about it. If you wanted to rob a store, what are all the things you'd have to take into account to be able to do this cleanly today? And this is theoretical. Don't be trying to do this. Right. Well, you have these AI powered cameras all over the country. You're first going to have to avoid these. Second, is the license plate reader. Third, your mobile device is tracking you at every single moment.
Then you have to take into account everything you touch with your hands are going to leave fingerprints. If I count the cameras that may pick up what you look like on the way they are on the way back. How could you possibly commit a crime today and not get caught unless they did not want to catch you? I mean you drive past these cameras, you would have to walk in shoes that they cannot identify because they did not link to your records of purchase history because they'll do this too. They did that with the Luigi Mangione backpack, I think, or something along the lines of this. I have no idea how crime does not get solved at 100% success rate today. I mean think it was the last time you left your phone more than 10 feet away from it. And now you lost your phone, but you got to drive to go do whatever the heck you want to do. Well there's a flat camera. I'll walk and where you pass 50 security cameras on the way there. Well then I put on a mask and we saw the purchase that mask on Amazon. Where you left fingerprints. I have no idea how crime does not get solved today. Would you say it's impossible to get away with the crime in 2026? No, I'm sure if you pay somebody enough, you see plenty of criminals running around today. In fact, we see them on the news all the time, huh? Sometimes they make our decisions in politics and sometimes they run the companies that me and you use every day. This is a scary thing with treating everybody as if they've already committed a crime, because it's flexible. In this late stage capitalism, it's flexible if you committed a crime, depending on who you are, because money reigns all. It's interesting to think about all the conspiracies around loan shooters and then all the conspiracies around people that are supposed to be dead, but some people speculate that they're still alive. Epstein, that's the one that comes to mind. I'm telling you, if we're going to find them, if you're still alive, this would be done through advertising technology. And how many people would have access to that kind of data? I couldn't tell you. You could buy access to it. Really? Me. How much do you think that would cost? Not in the grand scheme of things, not very much. Less than $10,000. And then they do you based on pure, perqueering, pure search? Well, I mean, people could buy access to the ones I was talking about earlier. Lexus Nexus, an experienced private investigators. Funny enough, they do diligence process for them. Some are very scrutinized, and some you can just make a shell company pretend and say you're doing something. And they will give you access. What's the one thing that everybody trusts that you never touch when it comes to technology? Yeah, your Alexa, your indoor spine device. Yeah, that thing does not come anywhere near me or my home. Alexa off. She does have plenty of privacy, doesn't she? Um, yeah, I mean, let's go back, let's go back in time, where the NSA was tapping into TVs and turning their speakers into microphones. You have an Alexa in here. Imagine if somebody wanted to get access to that. Imagine all the things that it listens to you doing. Imagine all the things it sees on the traffic, the network that you are on. I think it is essentially a spy. It's essentially a spy in many regards. Hey, but everybody has that thing. You can enjoy it. And this is not going to be in my house. You talked about Ford's patent earlier. And regards to cars potentially spying on people. Oh yeah, what's the most interesting patent you've ever read? I don't have many patents under my belt to be candid. It's the Flock one and the Ford one. The Ford one is quite egregious because it's going to happen across the board for vehicles because they had passed the law. I believe in 2021, which comes into effect 2027. Where they'll be using biometrics and facial recognition to identify if you were impaired before driving. They also say that data will not be shared, but biometrics and facial recognition, even scanning people in the back seat is kind of crazy, isn't it? What kind of surveillance state is that? You buy the product. Most people buy a car. They get it on the loan. They pay interest for it. It's a depreciating asset. And now it spies on you. And with that comes the remote disablement of vehicles. And so something you own is not even under your control anymore. They just shut down your car. Hey, for what? And they'll read whatever they want as long as you have access to it. I mean, I don't have many patents, but it's really crazy to think about that. Is it really ownership now? It's the same thing we see with property tax. You can purchase your house, pay off your house, hundreds of thousand dollars, millions of dollars. And if you don't pay property tax, you lose it. What is home ownership? We should change the word. The rhetoric surrounding it. What's a conspiracy theory? You 100% believe to be true. The One World Order. Where it's all going to come to one large group of individuals running the world. Across every nation. We already see this in ways today. Look at alliances that we have globally. I'm not specifically saying just what the U.S. but Latin America, China, Russia, European countries. There are alliances that cross beyond borders and beyond countries and nationalism. And broke into different identities that mesh people together. I think that may be part of the reason for America's collapse today. And why it almost seems pushed and forced. We have the world's currency. What if we could push everybody on to a digital currency? That is one step closer to controlling everything. And same thing for other countries. I won't get too verbose into the details. But geopolitics is something that our country is very heavily involved in. And it's not a today or tomorrow thing. It's played out near decades and advanced. That's why I tell people, you know, within the next 20 years, if there's not change, we will find ourselves closer friends with Russia and China than the EU countries. We have pushed propaganda against Muslims since the 60s. In 2020, the Department of Defense bought location data from Muslim prayer apps and Muslim dating apps to track their population in the United States. As we see the European countries having mass immigration from, well, other countries that are primarily Muslim, do you think we're going to want to work or be a friend? These countries when we were pushing propaganda against them for decades. At the same time as we slowly turn to the surveillance state that we would complain about for China in 2013, talking about how hellish and devilish it is. It's funny, people won't like this. I'm just holding up a mirror and people do not like what they see. You said identities that unite people across borders. What type of identity would unite someone in power? Yeah, it's primarily religious based. When your identity is based off of religion, it is something that's not malleable. It's actually the reason why we see the issues in Europe and Muslim culture. And it comes to immigration. Because when religion is your standing truth, your identity, it will not change, it's not malleable, and it cannot be amended regardless of where you go. And believe it or not, whether you like to hear it or not, people are tribal by nature. And so white men will make groups. Black men and black women will make groups. Christians make groups. This is nature in every regard. The problem is we just have unfairly distributed what is allowed to be done. I mean, look at the DEI stuff that we had for a very long time. And you see,
active discrimination against Asians and, well, white people when it comes to college admissions, while pushing up other races, being able to get into colleges. You can call it DEI. And what it is is racism and sticking towards specific groups for favor. We see the exact same thing with Indians. They ask you by that as work for an Indian boss. Before you know it, they will hire on other Indians. Jewish people are the exact same. So are Christians. Everybody is in this identity group that they naturally resolve to find and get towards. It doesn't mean you hate other groups, but it is tribalism and human nature. And 80 years of propaganda and modern media will never undo tens of thousands of years of biology and evolution. The problem is when these groups start persecuting others. You can keep this answer brief, but do you suspect eschatologies are important to this group of people? No idea what that means. Just the idea like how some groups view the end of the world. Yeah, no, I'm certain it is. I mean, think about the way the people act. If you believe in heaven or hell, this would decide on how you act on the world and your daily actions. If you don't believe in this at all, or maybe you want to die, you may be doing things that is heavily acting against what most people may want. In the end of the world planning, maybe there's a ritual. Well, there's no heaven or hell for you. Unless you make this happen, not everybody die. Let's slowly move towards it. Is there a group that does that? Probably. You said earlier in this podcast that everything you were saying now and releasing in your paper about flock, could put your life at risk and most likely will result in you going to jail. If this was your first and last podcast you ever did, what is the one thing you want people to remember walking away from this episode? Still time for change. It's never too late. I think it's silly because people get into a defeatist mindset. But there's so many things about our country that could still be changed. Privacy is a political thing. You need to be represented. Do not just become like a scared dog and accept defeat or think this is unable to be altered. Go out, participate in your local community and your city council. You can make a difference. This is part of being an educated citizen. It's kind of the issue with social media and people being so heavily knowledgeable about things that happen nationwide. They get mad at the government. They get mad at the federal government and the president or former presidents doing this, being mad, being emotional about change is nothing. Go to your local community where you can make a change where then it goes to your state and then to the nation. There is still time to make a change. You just cannot be inactive about it. Like I said, there is no revolution. It is a restoration. You do not want to go out killing people or tearing things down. You want to change them from the inside out and then prosecute those that obviously have trees in the country if found viable. You cannot completely absolve the political idea of this country through warfare, internal warfare, a civil war and expect it to work out well. And then what's the one thing you want people to know about you as someone who has just appeared online recently and kind of tries to keep their life as private as possible? I don't know. Let me tell you. What do you want people to know about you? If I were in a situation that I thought I was going to die, there's no about me and then there's what they should know for themselves. Those are two different things. I'd probably say that throughout this entire podcast, I was not guided by money and I was genuinely extremely curious. That's what I want people to know about me. But I'm curious I kind of hope I go to Joe. Everything is politically bound and I plan to join and campaign as an independent politician and nothing is more craved right now than authenticity by the American people. Nothing shows more authenticity than willing to act as a martyr against something so many people disagree with for national security above money. I'm willing to do it because it is the right thing. It is the American thing to do. What did Snowden face for what he exposed? Treason. Which is why he had to leave the charges for treason or it's a kangaroo court. You're allowed to tell them why you did what you did which he leaked national secrets top secret information and not allowed to know or take an account why you did that even though it was deemed illegal. The only thing they could judge is if you did it or not which is obvious. He exposed an illegal program but there is no beating the kangaroo court. That's why he left. You would never have true justice in the United States. If you were going to call it now, like how certain are you that you'll go to jail after this podcast? I'm on almost 100%. They have ignored the research that I've published because if anybody found out about it or they publicly acknowledged it. He essentially demolished his entire company. A dynamic surveillance network on all Americans that can't even keep its system secure. Nobody will buy this. And that is that is a part of this paper. People need to see how risky this is. And so I'm quite literally coming out and saying, you said you've never been hacked three times. I hacked you. Here is this database of every single location of every device. Now explain it. You cannot hide or use rhetorical challenges or manipulation when it is standing there in front of you, raw evidence. It's too big to ignore. It's why I've spent so much time making sure it is perfect. This is a matter of national security. What's the best piece of advice you've ever received? This kind of comes back to my childhood. It's something my grandfather taught me because I told you a little bit about my background. It was just to always be, how do I say it without sounding crazy? Always be curious about things and question them. But don't go crazy, like looking into the eyes of the beast and questioning all of reality is a more complex way of saying it. I don't even know how to explain it. Question things, but don't drive yourself mad doing it because otherwise you will trust things cluelessly. They may be leading you astray, but if you question everything, you will lead yourself astray. I think that's why I picked up so many different topics and knowledge over the years because I was just cannibalizing every single thing that I could ever learn. Well everyone, this has been your guest, Joshua Michael. This is the Jack Neal podcast. I appreciate you coming on brother. Of course. One absolute blast.
Podcast Summary
Key Points:
Flock cameras are marketed as license plate readers but function as a nationwide dynamic surveillance network using AI to track people, vehicles, and behaviors in real time.
A cybersecurity researcher discovered multiple critical vulnerabilities in Flock’s systems, including publicly exposed API keys and insecure authentication layers, giving access to data from 5,000 police departments, 6,000 communities, and 1,000 businesses.
Flock’s data collection includes facial features, clothing, vehicle details, and behavioral patterns, with the potential to generate detailed "person intelligence" profiles through platforms like Flock Nova, enabling deep tracking of individuals.
Summary:
, with over 335,000 cameras. These devices, marketed as simple license plate readers, use AI to track people, vehicles, and behaviors in real time, collecting vast amounts of data including facial features, clothing, and vehicle details. A cybersecurity researcher exposed severe flaws in Flock’s systems—such as publicly exposed API keys and insecure authentication—allowing access to nearly every American’s movement data across police, private, and municipal networks.
The researcher found that Flock’s systems could be exploited to track individuals nationwide, even without a warrant, and that the company repeatedly claimed to be unharmed despite deliberate, repeated breaches. Flock’s platforms, like Flock Nova, can generate detailed profiles of individuals by linking disparate data points, creating a pervasive and often invisible surveillance infrastructure. Despite public warnings and technical disclosures, Flock downplayed or ignored the risks, claiming it had never been hacked.
This raises serious concerns about national security, privacy erosion, and the unchecked expansion of private surveillance into public life. The researcher also highlights how data from everyday activities—like online searches or social media—can be used to predict personal life events, such as pregnancy, as seen in a 1990s case. With minimal regulation and poor cybersecurity practices, the technology poses a significant threat to individual autonomy and democratic freedoms, especially as it enables mass data collection and sharing across law enforcement and private entities.
FAQs
It locks in your makeup for up to 24 hours with a gel-to-mist technology that provides plump, dewy hydrated skin without stickiness or residue.
It offers a flexible, all-day grip that feels comfortable and natural on the skin, helping to maintain your look throughout the day without tightness or irritation.
A Flak camera is an AI-powered surveillance device that can track vehicles and people through facial recognition, vehicle features, or behavior, using data from a network of cameras across the U.S.
There are over 280,000 Flak cameras in the U.S., with more than 335,000 when including decommissioned units, and they are also present in countries like South Africa.
Yes, through a system called a Wing Gateway, Flock can integrate with existing IP cameras, such as those in gas stations or homes, turning them into surveillance nodes that feed into the Flock network.
Flock cameras collect license plates, vehicle features, and detailed data on people including age, gender, clothing, and actions. This data is stored and accessible to police departments and municipalities, often beyond public awareness.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.