Multiple residents and security researchers urged the council to cancel or pause the city's Flock ALPR contract, citing public reports of configuration errors, published CVE vulnerabilities and media investigations showing open camera streams or exposed search logs.
John Hamilton, a local cybersecurity researcher, summarized vulnerability reports and said many of the identified issues required hardware redesigns rather than simple patches. He and other speakers described published incidents in which camera feeds or search logs were publicly accessible and argued that such exposures show the vendor's security claims are overstated. "They lie to the public and city councils as a marketing tool," Hamilton said.
Opponents asked for a moratorium on expansion, independent audits, role-based access limits, retention clarity and explicit council review before any further deployments. Several speakers suggested the city seek contract changes to narrow vendor rights to derivative/anonymized data. Council members acknowledged the concerns and said staff and legal would keep monitoring security reports, audits and contract terms.
What proponents asked for: independent audits, clear retention and sharing rules, and council review before any expansion; what the city did: closed the workshop with no immediate contract action and asked staff for ongoing oversight.