Hook
On a Tuesday afternoon in late March, a Uber driver in Austin picked up a passenger, drove 12 minutes, and unknowingly scanned 47 license plates. The data — location, time, vehicle make — was uploaded to a private server owned by Flock Safety, a company that sells automated license plate recognition (ALPR) technology to police departments and homeowner associations. By the end of the month, that same driver will have contributed to a database of over 2 million plates, all without a single warrant, consent form, or disclosure. The passenger had no idea. The driver had no real choice. This is the new reality of the Flock×Uber "fleet scanning" program, quietly rolled out in pilot cities across the United States. And it is the single most dangerous precedent for surveillance-as-a-service I have seen in my 16 years watching decentralized technology fail to protect us.
Context
Flock Safety is a Atlanta-based company that has raised over $300 million, valued at $3.5 billion. Their core product: solar-powered cameras that capture license plate data and feed it into a cloud platform where law enforcement can search for suspect vehicles. The company claims its technology reduces crime by 30–40% in neighborhoods where cameras are installed. But the expansion into ride-sharing fleets turns every Uber into a mobile surveillance node. The driver receives a small monthly bonus for participating; the passenger receives nothing. The data is collected automatically, stored indefinitely, and accessible to police without judicial oversight. From a decentralization philosophy standpoint, this is the antithesis of everything we have been building. Ownership, consent, and transparency are replaced by aggregation, coercion, and opacity. The protocol is centralized, the incentives are misaligned, and the governance is nonexistent. The Flock×Uber partnership is not a product innovation; it is a infrastructure for control.
Core
Let me deconstruct this from a technical and values perspective. The system works as follows: Uber drivers opt into the program through a partnership between Flock and Uber's delivery division. The driver installs a dashcam-like device that captures license plates continuously. The data is encrypted in transit but decrypted on Flock's servers. From there, it is indexed by vehicle, location, and time, and sold to police departments via subscription. The driver is paid a flat fee — roughly $50 per month — for the privilege of acting as a data collector. The passenger is not informed, not compensated, and not given the option to opt out.
Based on my experience auditing smart contract governance mechanisms, I can tell you that this system violates every principle of consent-based architecture. In a decentralized protocol, every action requires explicit user approval. Here, the user (the passenger) is not even a participant in the transaction. The data is generated by the passenger's presence, but the passenger has no agency over its collection, storage, or use. This is surveillance by default, not consent by default.
Let's look at the numbers. Flock claims to have captured over 10 million license plates in its pilot phase with Uber. If the program expands to Uber's entire fleet of 3 million drivers, the annual data capture rate could exceed 1 billion plates. To put that in perspective, the entire US population of vehicles is roughly 290 million. Flock could re-identify every vehicle every three months — without any court order, without any transparency, without any audit trail. The data is stored on centralized servers owned by a private company. There is no on-chain record of access, no decentralized identity verification, no cryptographic proof of consent. The system is a black box with a key held by a single entity.
The core technical flaw is not the camera — it is the data model. Flock's architecture treats license plate data as a public good, but it is actually a private byproduct of shared mobility. The passenger pays for the ride; the driver provides the vehicle; the platform facilitates the match. The license plate data is an externality generated by the transaction. In a decentralized system, that externality would be owned by the user who generated it. The passenger could choose to share it, or not. The driver could be compensated for the use of their bandwidth. The platform could be a neutral coordinator, not a surveillance intermediary.
But Flock has built the opposite: a centralized data marketplace where the user is the product, not the participant. This is precisely the pattern that bitcoin and Ethereum were designed to break.

Now, let me give you a specific technical observation that most commentators miss. The Flock system uses a proprietary API to cross-reference license plates with external databases — including DMV records, stolen vehicle logs, and even social media scraped data. The API is not open source. The data schema is not standardized. There is no interoperability with decentralized identity systems like Ceramic or IDX. This means that the data is locked in a silo, controlled by a single corporate entity, with no possibility for the user to withdraw or correct their information. From a protocol perspective, this is a central point of failure. If Flock's servers are compromised, the entire database is exposed. If Flock is acquired by a company with different values, the data can be repurposed. If the government demands access, there is no technical barrier to compliance.
True ownership begins where the server ends. Here, the server is the only thing that exists. There is no local storage, no user-controlled encryption, no zero-knowledge proof of ownership. The entire system is a permissioned network with a single gatekeeper.
Contrarian
But let me challenge my own argument. Pragmatically, law enforcement agencies argue that Flock's technology has solved real crimes — carjackings, kidnappings, hit-and-runs. The data is often used to identify suspects within hours, something that traditional surveillance cannot achieve. The partnership with Uber expands this capability to cover more public space, potentially deterring crime. The drivers who volunteer are earning extra income. Uber is not forcing anyone to participate. The passenger is not identified by name, only by the vehicle's license plate — which is already visible in public. So what is the actual harm?
Here is the blind spot. The harm is not in the data collection itself; it is in the lack of accountability and the absence of exit. The driver cannot easily remove the device once installed without losing the bonus. The passenger cannot opt out of being scanned on a ride they need to take. The police can query the database without a warrant because the data is "voluntarily" collected by a private company. This is the classic surveillance loophole: if the government does the collection, it requires a warrant. If a private company does it, the Fourth Amendment does not apply. Flock is effectively privatizing the warrant requirement.
Debate is the compiler for better consensus. We need to debate whether the trade-off — convenience and safety versus privacy and autonomy — is being made by the right people. Currently, it is being made by a corporate board in Atlanta with no public oversight. The Uber driver is not a stakeholder in the governance of the data. The passenger has no vote. The only entity with meaningful control is Flock's C-suite.
Furthermore, the scalability of this model is terrifying. Once Uber's fleet is fully instrumented, Flock will have the largest continuously updated vehicle location database in the world. They can track movement patterns, identify regular routes, infer social connections, and predict behavior. The data is not just license plates; it is a behavioral map of every city where Uber operates. And because the data is stored indefinitely, it can be mined for patterns years later. This is not surveillance for crime solving; this is surveillance for prediction and control.
Takeaway
We are building permissionless, trustless, censorship-resistant systems precisely because we do not trust centralized entities to manage our data. The Flock×Uber plan is a reminder that the real world is still running on permissioned, trusted, centralized infrastructure. The blockchain industry has spent years solving digital ownership — but we have not solved physical ownership of generated data. Every time you step into a ride, your data is being harvested by a system you cannot audit, cannot govern, and cannot exit.
The question is not whether Flock's technology works. The question is whether we are willing to build a decentralized alternative that gives users control over their own surveillance footprint. I am not optimistic. The bull market euphoria has made us forget that the real battle is not about token prices — it is about who owns the data of the moving world. If we do not build a decentralized, consent-based license plate registry, Flock will own the map of every public street. And we will be the nodes in their network, not the owners of our own data.