Video summary
This episode of ThinkTech Tech Talks explores the growing prevalence of AI-driven street surveillance in Hawaii, featuring insights from Cypac's Itila Sures regarding companies like Flock Security that deploy Automated License Plate Readers (ALPR). While these systems are often justified for legitimate public safety purposes, the discussion highlights significant risks where data aggregation between private corporations and government agencies creates detailed profiles on individuals. A critical concern raised is the potential for AI to "hallucinate," leading to false identifications such as mistakenly flagging a minivan based on erroneous matches with stolen vehicles from other states, which can result in innocent people being targeted by law enforcement without proper oversight.
The conversation delves deeper into how these unmonitored AI agents categorize individuals, including teenagers, as high-risk threats and facilitate real-time surveillance that effectively turns private entities into government extensions. This invasive ecosystem extends far beyond street cameras to include location tracking via smartphones and AirTags, social media monitoring, and advertising algorithms that analyze user behavior in microseconds. Furthermore, the episode points out a troubling bias in camera placement, noting that devices are disproportionately concentrated in low-income neighborhoods rather than affluent areas, which reinforces existing prejudices by training AI models primarily on crime-heavy zones while ignoring safer communities.
Security vulnerabilities add another layer of risk to this surveillance landscape, as companies may utilize stolen data from the dark web or suffer large-scale hacks similar to those experienced by major tech firms like Microsoft and Meta, allowing unauthorized access to sensitive information. Despite acknowledging potential benefits for local businesses and public safety, Sures argues strongly against unchecked surveillance due to severe privacy risks and a lack of accountability regarding data retention policies, specifically concerning how long data is kept before purging. She advocates for the implementation of systematic regulations through third-party audits comparable to the CMMC certification model to ensure secure configurations and proper disposal of sensitive data before deployment.
The episode concludes with host Jay Fidel thanking guest Attilio Cypac for addressing the critical issue that hacking and surveillance represent fundamental invasions of private space, emphasizing the need for common sense safeguards and improved digital hygiene practices for individuals in Hawaii's strategic position as a gateway to Asia. The segment wraps up by calling for support for businesses seeking protection against cyber threats while reinforcing the necessity for balanced approaches that protect civil liberties alongside security interests before signing off on this important discussion about AI-based street surveillance both in Hawaii and elsewhere.
Read the full video transcript
[music]
Welcome to Think Tech Tech Talks on
Think Tech Hawaii. I'm your host Jay
Fidel. This episode is called AI based
street surveillance in Hawaii. This is
being done across the islands by
companies such as Flock Security. Our
guest for the show is Itila Sures of
Cypac. Welcome to the show Itilla.
>> Thanks for having me, Jay. I appreciate
it. Always glad to help. And you
[clears throat] know, I I hope that your
viewers find this episode interesting
because I certainly think this is an
important topic.
>> Let's talk about Cypac and why CYPAC is
interested in AI based street
surveillance in Hawaii.
>> ALPR is a uh is a technology that's been
around for some time and we've worked
with it in different capacities. ALPR,
oh man, that's a that's a mouthful, but
what it really means is it's an
automated license plate reader. It's
super handy in service centers. So, if
you're to drive your car into a service
center for an oil change, they see your
license plate. They're able to bring up
who you are. They say, "Hey, thanks for
calling, uh, coming by, Mr. Fidel, with
your, you know, nice vehicle. Please,
uh, pull up and, you know, we'll service
your vehicle. We see that it's, you
know, you have an appointment, etc.
These kind of things are really useful
for automatic license plate readers. The
problem is that uh there's uh there are
private companies that have set up
inconspicuous cameras all throughout the
country and they're using that same
technology to gather uh everything from
not just your license plate but any sort
of damage you might have on your car. Uh
they create heat maps of where you've
been and where you're going. And uh then
they also do predictive modeling to
figure out where they think you might
go. And uh that allows them to create a
profile about you. For example, what
church you go to. Uh which can then of
course figure out uh what kind of
religion you might ha uh might have. Uh
if in on the mainland, this is a real
issue with abortion uh clinics who are
having uh people who are coming from out
of state coming to those abortion
clinics. And uh where this becomes an
issue is because this is a private
company, that means that that data is
for sale. And our federal government uh
typically would require a subpoena to do
this level of surveillance on an
individual or a group of individuals.
And uh instead uh the loophole is that
they can buy this data from a private
company. And because they are buying
this data from a private company that
allows them to uh with some degree of
confidence perform arrests. And so this
has been happening for example for ICE
uh to find people who are um who
potentially they could deport. So an
example was for example there was an
individual who was of Hispanic descent.
He uh went to a Home Depot to buy uh I
guess uh materials to go do some sort of
uh handyman work. And as he was leaving
Home Depot, uh he was arrested by ICE.
And it turns out that Home Depot had had
some of these ALPR cameras installed in
their parking lot. And uh that license
plate and a description of his vehicle
was sent to ICE agents who was then who
were then able to find out all the
whereabouts of this vehicle in the past.
Then they took that information and
deduced that this was an illegal
immigrant and then subsequently deported
him. And that's uh that's one way where
you can see where private corporations
uh and federal agencies are
collaborating with a third party private
data gathering organization to make
arrests and make assumptions about
people's behaviors. And by the way, it's
not just Home Depot. It's Walmart and
many other retailers and other kind of,
you know, big box stores that are
installing these uh these private ALPR
devices. And of course, Flock is one of
many companies that's doing this. And
this is just a sign of the times. It is
going to get a lot more interesting
because AI is on everyone's mind. Well,
guess who's doing this work? It's AI
agents. And AI agents, as we know,
sometimes like to hallucinate. Uh I know
Jay, you're you're in you have a a law
background and one of the big hot topics
has been uh how AI is going to influence
the legal community, right? Because it
can do the research for you. However,
some attorneys I've heard have become uh
they got in trouble because they used AI
agents as uh to gather supporting
evidence and they presented it in court.
But what they didn't know was that the
AI agents had hallucinated facts and
cases and uh when they presented it in
court, it turned out to be not factual.
And so AI can with a great degree of
confidence say that something is true.
And it sounds very believable, but it
might not be. And case in point with
Flock is that these ALPR readers uh were
reading a uh a woman's license plate.
This was a couple years ago in Colorado
and she was in a parking lot with her
kids and I think she was trying to find,
you know, something on her phone. So
she, you know, lawfully pulled over into
a parking lot, was checking on her
phone. Next thing she knows, she looks
up. There's police all around her car.
They force uh her and her kids out in
gunpoint, put them on the ground, and
this is all on YouTube, like you can see
this for yourself. They point them all
on on gunpoint and say and uh you know,
put them under arrest because it turns
out that her minivan
happened to have the same license plate
number as a stolen motorcycle from the
next state away. So from few hundred
miles away, someone had stolen a
motorcycle and AI had somehow
hallucinated that this minivan was
indeed the stolen motorcycle and to go
get him. And uh there's been numerous uh
accounts of that where AI has
hallucinated
specifically under Flock and led law
enforcement on these wild goose chases.
And by the way, Flock is just one of
many technologies out there. There are
technologies that are listening devices
that listen for gunshots uh which have
had a very also you know controversial
um success rate and it goes on and on.
>> Well, that raises a lot of questions in
my mind. Um you describe a a scenario
where um uh
uh they they know the government knows
almost immediately that there's somebody
in in Home Depot or wherever it is uh
who might be an illegal immigrant uh
almost immediately. Well, that means
that it's live. It's real time. and
there's somebody sitting in uh uh in in
home in somebody's sitting in the
government watching the screen that the
screen is being tipped off uh in real
time. So it's not as if they're looking
at this every third day. They're looking
at it right now within minutes. Am I
right?
>> It's even worse than that. It's not even
that they're looking. is that you have
AI agents looking and then based on what
the AI agents think your risk level is,
they'll put you on a high risk category.
So, there have been examples of
teenagers who have had a small uh
offense, a small minor offense, and now
AI agents have decided that they are a
high-risisk threat and they keep sending
police out to their house to harass
them.
So, it's not even so much like they're
watching you. It's AI is watching and
deciding that you are a threat based on
whatever criteria it deems as uh as
valid and there's NO OVERSIGHT. YOU
KNOW, it sounds to me like um these
cameras in Home Depot or elsewhere uh
and the organizations that uh that um
install these cameras are acting as
quote agents end quote legally agents
for homeland security. And if that's the
case, if you could make that case that
they're really acting for and on behalf
of u of homeland security, then it's not
so much a private organization, is it?
Couldn't you make the argument? Are
people making the argument that in fact
this is the government?
>> Well, that that's the loophole, right?
So, the government can buy data. And by
the way, this is not by far the only
data gathering entity out there. Uh you
and I do a lot of things on the
internet, right? We post things on
social media. Uh we do these kind of
interviews and and we say things, right?
And everything that we say is
transcribed and archived and put as part
of a data set about who we are. So if
someone wants to know about Jidell, then
it's that I promise you all the all the
transcripts that you've uploaded to
YouTube of all these interviews and the
things that you've said, it's all been
data gathered and is searchable and AI
has interpreted who you are and what
your preferences are and what might be
important to you and what might not be
important to you. maybe your health
information and all that stuff is sold
in real time uh for advertisers, for law
enforcement is available for any for any
reason. I'll give you an example. Have
you ever noticed that if you've ever
gone on Amazon or eBay uh perhaps you
may have searched for something a week
ago and then magically on your Amazon
homepage there's a product that meets
that demand. You know, let's say you
have a backachche and you search for the
you you search like why do I have a
backachche? Next thing you know, two
days later on your Amazon homepage,
there's some, you know, backachche
stuff, you know, your heating pads or
Advil or whatever. How did that happen?
It's because there are micro bids that
occur. So, when you go to Amazon, Amazon
says, "Hey, I got this guy Jay. Um,
you know, what can you tell me about
him?" Well, Jay has a backachche. Well,
wonderful. Okay. Um, who here on the
Amazon marketplace wants to uh sell Jay
some Advil? Advil says, "I'd like to do
that, please. I'll pay 2 cents for
that." Wonderful. Okay. Now, I'll put
that ad for Advil right there on uh on
the homepage for Jay when he goes uh to
his Amazon.com account. And that occurs
in micros secondsonds in real time as
you go to that site. And that's like one
example that's 20 years old. This has
been around for a long time.
>> What about phones? Um, you know, in your
notes and your comments on the in your
media media appearances, you talk about
phones. How do how do phones and
location um location data click into
this whole system?
>> Well, we all love Google Maps. We all
like to look at the traffic. Look at the
H1 and it's green. Hey, hey, that's
good, right? But then sometimes it's
red. Sometimes it's yellow.
Where's that coming from?
Where do you think
it's your phones? How fast are the
phones moving on the road? And so there
are some really useful um data gathering
information that's real time that we get
from the benefit of everyone using these
phones. I love Air Tags, right? You
know, if you ever travel and throw one
inside one of one of those suitcases,
when it ends up at the wrong airport or
it's lost in luggage, hey, those Air
Tags are lifesaver. It also depends on a
vast uh network of millions of iPhones
out there that are all talking to all
the Air Tags whenever whenever uh you
walk by them. So, that kind of
communication
can be very beneficial. Uh on my post
from a couple weeks ago, uh we did talk
about this and uh in my you know, in my
opinion, you can't stop ALPR
cameras from recording you. And if it's
not going to be Flock, it's going to be
some other company. Uh because they are
private companies and they come up and
they they you know, they're just going
to keep coming. It's a startup. But one
thing that you can do is change the
privacy settings on your iPhone or on
your Android, so that way you don't have
rogue apps gathering information about
you when you don't want them to. Um,
have you ever noticed how sometimes
you'll bring up a an app like uh maybe
some game and uh you know on that uh on
that Blockbuster game you you decide, oh
well, why does this game need access to
my contacts?
Well, why does it need access to my
location? Why does it need to do data
sharing amongst my other apps? Like,
what does it need to gather data from my
pictures and my photos and my social
media apps? Like, what is this game
trying to do? It's harvesting your data.
No such thing as a free game. It cost
them money to put together. Where do you
think they're going to get that back
from? They're going to get it back from
getting data about you and then selling
it to advertisers and repeating the
process.
So this is an ecosystem.
>> Does ALPR data integrate with the phone
location data? In other words, when uh
when these guys are selling data about
me, um are they also selling data they
got from my phone? And let me add, by
the way, you should explain that this
location data may be available even if
my phone is off. Remember Pegasus?
Remember Pegasus? Oh, there's there's
been a few iterations since Pegasus for
sure, but uh yeah, Pegasus,
[clears throat] for anyone who's who's
uh who uh who doesn't know about it, was
a um was a [clears throat] package that
was deployed uh by an an Israeli firm.
Uh and what they were able to do was
send a text message to any phone that
was unpatched. It just doesn't work
anymore. And essentially that one text
message would allow them to completely
take over the phone. So as long as they
knew your phone number, they could
completely take it over. And that gave
them backd dooror access to be able to
do whatever. And that text message of
course would disappear. And they were
targeting journalists and politicians
and other people. And this was iPhone
specific.
um
with Flock in particular because he
asked you know where they were getting
some of this data from. They can get it
from data brokers. Uh so you know I
mentioned earlier how a game might
harvest your information and then send
it off for sale. They have been
purchasing data about you to combine to
create that profile. And furthermore,
they got in trouble because not only
were they using legitimate data that was
gathered and sold to them, but they were
they were using illegitimate data from
leaked or hacked companies. So they
would find data about you on the dark
web, siphon that out, and use that to
build your profile. So it was it was not
just purchased, but stolen data about
you as well. You mentioned there are 43
plus I don't know what that translates
to in actual numbers uh of these flock
phones or surveillance phones in the
state of Hawaii. I mean my understanding
is there's there's tens of thousands or
even hundreds of thousands of phones but
they're real surveillance phones and
they work on an internal network of you
know for a given company or
organization. Um this is different
though this technology is different.
what's the difference and how does AI
play into these 43 plus phones?
>> So, we're talking about the ALPR cameras
that are kind of spread throughout the
state of Wahoo. I was looking at the
map, too. Um, and it's it's fascinating
because they're not evenly distributed
the way you would think. It's not like
they just took these ALPR cameras and
just, you know, took a took their hand
and just, you know, threw it out onto a
map and distributed them evenly. They're
in kind of low-income neighborhoods. So,
for example, in the city of Honolulu,
when I checked last, there were like
three of them throughout like downtown,
but then I noticed in Eva Beach, there
are three of them on one specific road,
but PP road, which for anyone who's from
Eva, it's Hal Bush, right? And Hal Bush
is, as we know, is kind of a little bit
of a a little rogue town. So, there's
some interesting characters down there,
but they put three of them down there
specifically. So, what's that about?
Right. So, and that's been one of the
criticisms of Flock is that they're not
evenly distributing these cameras to
track people and maybe u you know,
moderate or high-income neighborhoods.
They're targeting uh you know
workingclass or or or you know lower
income neighborhoods and and kind of
amplifying the problem because of course
they are a what startup. They're what a
private company. They want to show
profits and and data. Well, if you're
going to put together a surveillance
company to surveil people, the metric of
success would be either arrests or
stopping crime, right? Well,
if if there's a uh a a a good upper
middle class neighborhood, there's
probably not a lot of crime there. You
want to put these cameras in the in the
in the crimeridden places and then catch
those criminals as as it stands, right?
And those kind of activities are going
to then make their product look good.
So, it makes sense from their
perspective why they're putting it into
maybe a lower or workingclass
neighborhood where there could be some
of these uh things happening already.
And, you know, that makes their product
look good, but it it it's really u you
know, biasing people. There there's also
kind of like this conversation that I've
um and I've read online where they talk
about you know, you know, we talk about
biases. Now, AI is going to inherit
those biases. So, if a bunch of cameras
are in, you know, low-income
neighborhoods and they see all this
crime, well, guess what it's going to
assume? Anytime you put that camera not
in a low-income neighborhood, anytime
someone who matches a visual description
of someone who's there, the AI engine is
automatically going to assume, oh, well,
that's that's a criminal, right? So, is
that the kind of world you want to live
in? It's it's but this is the direction
we're going. The whole thing is scary.
But let me let me just try to get my
head straight on how the AI works. So
the AI would be on the camera and the
camera they use for this kind of
surveillance has AI built into it. And
so it is going to look for a license
plate on a car, maybe even look for a
face behind the windshield. Um, and it's
it's going to be using AI to identify
somebody who is in the language model,
right? Um and then then you say that
that is purchasable, transferable to
some government agency or somebody who
wants to buy it and are they using AI
also um in identifying this person, this
license plate um and you know uh
examining the data, this social social
networking analysis type of data um
[clears throat] to put it all together
Is is AI at both ends of this
transaction or just one?
>> Yeah, I think it's important to remember
that AI is not a black box.
Think of AI as doing what a human can
do. So, a human would be able to look at
a picture of a person driving
[clears throat] their car, look at a
license plate, write down that license
plate number, and then say, "Oh, where
where else can I look for this?" Oh,
well, there's there's another
spreadsheet here I have or database I
have that I can put that, you know, the
license plate into and then I get a
name. Oh, okay. Now, now I have a name.
Now, what can I find out about that
name? I don't know. Let's Google search,
right? Google search the name. It's
called Google Derking. Put in the name.
Oh, wow. I know where this person lives.
His email address. Great. Oh, look. He's
got a family. Oh, let's look at public
records. Oh, this person just got um
married last year. Interesting. Oh, and
they just purchased a house. Oh, look at
this. Check his credit report.
>> Is this Flock you're talking about?
Flock has that.
>> Flock is facilitate facilitating one
step of the process, right? They're the
ones that, you know, they, you know,
pinball machine analogy. They're the
ones that pull back the pin and release
the pin. Now, it all goes inside the
pinball machine. The cat's out of the
bag. The the pinball's bouncing around
and they're checking all these things
out. And at the very end of that entire
chain, they could say, "Look, we got
this person." And then based on our
analysis,
which is AI driven, right? Um, this
person's a threat.
And uh, all ICE has to do is say, "Hey,
you know, flock, we're going to give you
a million bucks for access to your
database. Show us everyone who's a high
threat target." And they could say, "Oh,
this person is is a high threat target."
Well, this is someone that we should go
uh go uh go arrest. Where is he right
now? Oh, he just left Home Depot. Let's
nab them.
>> Well, you say a million dollars. That's
very interesting because, you know, it's
two cents for a transaction over here,
but it's a million dollars for open
access. The open access troubles me. You
talked about lawyers making arguments.
And I would say that if I pay a million
dollars and it opens it up for me, uh,
then they become arguably my agent. I in
the legal sense. Um, and [clears throat]
all of a sudden, um, you know, flock is
my agent. It's really doing the
government's work.
And I could make the argument in court
um that that Flock must abide by my
civil rights. They can't do this as a
private company. They're no longer
entitled to the protection of a private
company. Don't you agree?
>> The rules are the problem here. So the
rules state that that private
organizations are allowed to sell
information to federal agencies and uh
you know there it's just one of those
kind of things and I think that there
are some you know we don't know exactly
how much uh is being sold to who because
that flock is kind of keeping that close
to their chest. Uh, but I I promise you
Flock is just one of many and there's
going to be more and we're in this AI
space where it keeps getting better. Uh
just this week for example uh Microsoft
released an entire uh writeup on how
hotel Wi-Fi
uh conference center Wi-Fi like you know
like Blazedale conference center Wi-Fi
and airport Wi-Fi many have been
compromised and hacked by Russian
hackers and they're doing that
specifically to snoop and redirect users
to harvest their Microsoft 365
credentials
and that was 100%
thanks to AI that gave them the option
the ability to do this at scale and uh
of course we heard about hugging face
and and uh how you know open AI got in
trouble for that but just this week
Meta's AI engine broke out and did the
same thing. So these these AI agents are
able to hack and and deliver things in
in such a way that we've never seen
before and we're just at the beginning
of that. AI is still uh in the corral as
we would say, but it is starting to
break out and once it once it goes full
tilt, we won't be able to stop it. You
mentioned the uh interstate issue about
um identifying a license plate from one
state uh that was used on a motorcycle
versus another state where the license
plate appeared on a car. Isn't the AI
smart enough to distinguish between a a
mo a motorcycle and a car? Uh was that a
failure, a hallucination? Um and it
sounds like this is imperfect. And if I
was the victim here, that is a member of
the public, uh, where I was being
victimized, um, I guess I should do some
discovery and find out where this was
taken from and whether it might be a
hallucination. And if I had a claim,
listen to this, Attilla, if I had a
claim, I would go against a private
company. It's hard to sue the United
States. It's hard to sue the government,
especially with this Department of
Justice. But if I [clears throat] could
sue Flock because Flock had a
hallucination and turned it over to the
government, then I arguably I could go
against Flock, why wouldn't I do that?
>> You can, but Flock's not the only one.
And this is going to go on.
>> Of course, of course.
>> I I I think where where Flock has had
some success, though, is that they have
uh police departments paying them to
[clears throat] put up these cameras.
And so it's anywhere from 2500 to $3,000
per camera, uh, which is what they pay
for the police department to have access
to this because, uh, let's just be
honest, it really does,
uh, reduce local crime. Like it it can
do that. Um, but like you said, the
hallucinations, it's a real concern.
Uh, how it's being used, that's also a
real concern. Also, while we were
looking here, I just double checked some
facts just to make sure we're all on the
same page. And yeah, it turns out that
ICE gives access they they receive
access to this data that we described
for free. So, they're not even paying
for it.
>> Oh,
>> yeah.
>> Why why they do that as a public
service? What is why do they stay in
business? How do they stay in business
if they doing it for free?
>> It's part of their I guess community
service. But one thing for example that
is happening is uh I believe in Southern
California if you want to open your
business then you have to install
cameras inside of your business and give
access to uh this is a different company
it's just like flock but you have to
give them access uh to your to your
cameras and you have to give that access
to HPD and so every business from like
Chick-fil-A uh to other fast food
restaurants all have cameras inside that
police departments have access to in
real time for any reason that they want.
>> Sounds like uh the protection racket in
reverse. Honestly, it does. Um but you
know, you talk about other states, you
talk about um you know, Russia uh and
hacking from afar. Seems to me that
Russia might be interested in you or me
and Russia could get online and bid for
our information across the pond, across
the miles, and they could know
everything about us, where we are, where
we go, what we do. I get a real profile
from a company like Flock. Uh, is that
happening? Or could it happen?
>> It's already happened in my opinion. And
I wouldn't I wouldn't look at miles
anymore. The world is kind of flat. it
has been for a while. Uh mass
surveillance uh in the interest of
public safety is always been a slippery
slope. Uh so you do want to think about,
you know, where's the trade-off between
your privacy and uh and and safety. Uh I
I think uh we've had a real challenge
with uh protecting our public because
the police departments have had funding
issues and it's a difficult job. Let's
just be honest about that. And so if
there's any sort of technology that can
make them safer,
uh then of course why would they not use
it? Uh we do the same thing for medical
technology. You know the medicine has
come a long way in the past few years.
AI has also helped to accelerate that.
Same with manufacturing. Same with
software development. I mean, our world
is really changing quickly. Why wouldn't
law enforcement try to jump on the
bandwagon and use some new technology so
that they can make us safer? The problem
is with all new technology, it's got
bugs.
>> Draconian uses um you know, malice of
forethought. If I Russia wanted your
information, I don't think it's got a
good purpose in mind. Uh it's got a bad
purpose in mind. Uh, is the government
doing anything to protect us? Is anybody
doing anything to protect us? Is the
ACLU doing any [clears throat] is CYPAC
doing anything to protect us? Well, we
definitely do our best to protect those
uh in the business space and that is a
that is also a really big topic because
uh you know what we're talking about
here is uh you know personal protections
uh but organizations if they are
breached then it's a real problem. So
this is where you know uh building your
business and operating your business in
a modern way is really important. Uh
it's in a safe way. It's in it's in a
modern way. It's in a way that's aligned
with best practices to keep your
organization from having a disaster. Uh
so that's that's kind of our focus here.
But uh these are things and you know Jay
I I really like to focus on topics where
you can do something about it. And if
you introduce a problem like this like
flock security, I mean you and I can't
go up against flock and I believe that
what they are trying to do is is good
for us. But the the the uh the Pandora's
box unfortunately has a lot of uh you
know dark side effects that it's hard to
mitigate. But, you know, at the same
time, like, do you uh do you throw away
the the baby with the bathwater? Like,
do you say that we're going to live in a
less secure society uh and allow people
to die or get hurt uh when it could have
been prevented with a piece of
technology. It's it's a hard uh it's a
hard line to walk, but uh I believe that
if we do our if we do our part to kind
of protect our individual selves by
doing basic safeguards, you know, don't
don't do stupid things on your phone, on
your computer.
Uh if if you're going to text and drive,
you know, please don't put your phone in
the trunk or get a self-driving car. I
mean, there there's there's other
options here. Uh, so I I think a common
sense is going to make us a a real safe
society as well. And I'm definitely not
going to uh, you know, oppose law
enforcement uh, for you know, using new
technology to try to make us safer.
>> Well, you mentioned that Flock was one
of many. You've repeated that. Um, and
you've mentioned that there are 43 plus
cameras. I guess that's under flock or
maybe it's under all of them but um
there's the question of aggregate
tracking and I'd like your thoughts
about aggregate tracking. So, I'm
company number one, call it Flack, and
company number two, call it Flack 2 or
somebody else. And they collaborate,
they aggregate. Uh they watch you from
Home Depot to uh Lowe's Hardware and
back again. And and they're getting a a
a picture, a signature, a location
signature of you wherever you go and
what you do. Even though even though
Flock only has the say 43 cameras,
whatever it is. So is it is it that one
agent in one in one surveillance company
contacts another agent and another
surveillance company says, "Hey, I want
to know about Aillaa. I want to know
where he's been today. Can we please
aggregate our data? Can we please
collaborate um to make a map of where
he's been uh as he passes by all of
these cameras?"
>> Yeah, it's all possible. And and we
don't have to talk about, you know,
obscure, strange uh companies. I mean,
let's talk about Ring.
Who's got a Ring doorbell? Lots of
people. We got a Ring doorbell. So, that
Ring camera feed gets uh stored in the
cloud.
And what if there's a crime in front of
my house?
Police can subpoena that video feed and
they can see it. Uh, in fact, I've heard
on the mainland that uh Teslas have been
towed from a crime from if if a crime
takes place because police show up and
they say, "Oh, all these Teslas, they
all have cameras that turned on when
there was a uh a crime that took place
here. Let's just tow all these cars and
and impound them and then we'll take the
video feed off the cars because it
supports the crime." Now, if you're a
Tesla owner, that kind of sucks for you
because you show up and your car is
missing, but at the same time, your car
has performed a valuable service and
that it's been a essentially a a a
security camera on wheels and it's
picked up potentially a crime that took
place. So, uh again, where where do you
draw the line on on this one? It's it's
a tough one.
>> Well, even [clears throat] if you wanted
to draw a line, could you really draw a
line? uh could you make a policy that uh
you know regulates this uh because you
know the department of justice in fact
the federal government now is not as
credible as it used to be. For example,
if they say uh that the flock has no d
no direct contact with ICE, um uh does
HPD have direct contact with ICE? is
is it an open, you know, an open channel
between the two of them or all these
companies and they're they're just
collecting everything um and they're
keeping it somewhere and they say HPD
says there's a 90-day purge um you know
on all this data, but in fact, you know,
you may or may not want to believe that.
Maybe it's not a 90-day purge. It's uh
it's something that you have to
question. and this says, "Well, you
know, if you want to keep it longer than
that, you got to get written approval
from the the chief of police, from HPD."
Really? Uh, and he has to decide that
it's not being used as evidence, uh,
quote evidence if it's, you know, it's
going to be purged. So, um, do you
believe that? Uh, and I I suggest to you
that notwithstanding statements, noble
statements that we're going to we're
going to throw this away, we're going to
purge it, we're not going to use it in
the wrong way, there's nobody monitoring
that. And when they say we, you know,
that we'll we'll we'll purge it. That
you can't you don't know if they're
really going to purge it and he's got to
decide that it's not evidence. Well,
maybe he won't make that decision. Um
what what I'm saying is that uh you know
you you got to trust government to say
what they're doing and uh and then maybe
these days federal and state you can't
and county you can't really trust what
they're saying that they will do. So
it's sort of an open book I suggest to
you and granted it is a theoretical
benefit in stopping crime, stopping
violence, making our, you know,
community more of a civil society and so
forth, which is all good, but it just
seems to me there's something very
draconian about the conglomeration of
all this data and the u you know the
purge uh and you called it the side door
loophole uh where they're not supposed
to be contracts, but there's wink and
blink contracts all over town about it,
how the data moves and who pays who
about what and who keeps it and whether
you can get it and do you have to file a
Freedom of Information Act or do a
subpoena to find out if you got nailed
improperly and so forth. I think as you
say AI is just at the beginning, but so
is the regulation of this kind of
technology at the beginning. So that's
why I'm going to make you speaker of the
house. I'm going to make you speaker of
the house today. I'm going to say,
you're Speaker of the House. What do you
do to regulate this? What what bills do
you encourage? Uh what what uh statutes
do you want to see adopted in order to
protect the consumer to protect the
ordinary Joe? protect yourself
um you know from improper use and
violation of your your civil rights
because we have to live in a country
that abides by the rule of law and we
have forgotten so much about the rule of
law it has been torn from us and this is
part of that you'll have to agree so as
a speaker of the house I mean in a in a
in a in a in a in a legislature that
abides by the rules that's open to
protecting the public what what
regulation would you try to do?
>> So I believe that prevention is the best
uh
prevention is the best option and I'll
give you an example. Uh I talked to a
property manager once. Property manager
came to me says you know what is the the
best eviction? I said what's the best
eviction? He says not letting a tenant
into the property was going to be a
problem in the first place.
So uh this has already begun in the
government space. So that means that
companies who wish to participate in
federal contracts are now subject to
something called CMMC the cyber security
model certification. That means that a
third party has to come in and say look
are you guys doing all the things that
you say that you're doing to protect our
our you know our our country's secrets
and then if so you get a little check
and then now you can go participate. You
can go you can go play in the uh in the
amusement park and [clears throat] many
of our infrastructure hacks. So I'm I'm
sure you hear about them like water
systems, power systems, they're all
being compromised because ah they just
threw in these PLC controllers or they
just threw in this other piece of
equipment. They left the username and
password default, right? Admin password,
connected it to the internet. Hey, who's
going to find this? Well, guess what?
It can be found. especially with AI. So,
um if you want to regulate companies
like Flock, then having third-party
assessment, having criteria, having
basic safeguards and and standards, and
then, you know, putting together the
funding to have auditors come in and
make sure that they are doing what they
say that they're doing. Like for
example, you said, "How do you know that
after 30 days uh the video feed is being
erased?" Well, an auditor could come in
once a year and say, "Okay, show me show
me the logs of your show me your purge
logs." And uh for example, in CMMC, if
you dispose of a piece of equipment that
has some private sensitive data on
there, you have to show that it was
properly disposed of through e-waste. it
was erased prior to being uh sent off to
uh recycling. Right? So that same
process can be applied and this is why
I'm saying this is not a hard problem to
solve. But it has to be done
systematically. You have to have some
sort of repercussions to it. And if
flock wants to continue to operate as it
does without oversight, that's really
that's really on us because we should
have said before you can put a camera up
on the road, we need to we need you to
demonstrate evidence that it's a
configured correctly because many of
these flock cameras have been hacked by
uh you know some fairly techsavvy people
who just drive up next to the camera and
tie right into the feed and start
streaming off of it because it's
available. like they didn't set it up
correctly or in a secure way. So if
those safeguards were in place prior to
them going onto the onto the streets, uh
if an auditor were to come in on a
regular basis and ensure that they were
accurately disposing of information that
they they could audit like where they
get their information from and you know
do all these like safeguards that they
say that they're doing then that would
be a much safer product because that
would set the precedent for the next
flock and the next one that's about to
come along and Ring and all the other
Amazon and the Google's and all the
other ones that are jumping in on this
space because let's be honest, there's a
lot of money to be made here. There's
some benefit to the community. We just
need to make sure we do it in the right
way.
>> Yeah. And and as far as the individual
consumer is concerned, I I'm hearkening
back to a time when the military
uh was trying to protect its own data,
its own radio signals during a war for
example. So what they do and this is in
use today for various applications where
they change the frequency you know 10
times a second whatever it is right I'm
sure you're familiar with that so you
change a frequency and nobody can really
follow you for more than you know one
iteration of those changes and so the
same thing here suppose I came to you
and I said look I got an idea my idea is
I I'm going to change something in my
phone I'm going to change something in
my I don't know in the transmission of
the data that that these guys are
taking. Um and I for a dollar and a half
I will protect you from that. I will
give you protection against those who
are sucking [clears throat] up your data
and selling it. That would be that would
be very interesting and attractive,
wouldn't it? Uh is that doable? Is there
anybody doing it? There are some uh
services out there that allow you to
erase or or they do their best to try to
erase your digital footprint. It's
called digital exhaust. So your digital
exhaust is everything you do and it's
kind of, you know, the that as as the
name implies, it's it's kind of like a
trail of what you've done. And so there
are a few brokers that can, you know,
help clean that up for you. Uh but
again, if we had better standards in
place, I mean, let's just kind of go
back in history. You don't have to go
very far. FDA. Where did that come from?
These people were eating, you know, a a
can of beans and dying the next day.
Why? Because, you know, there was no
standards to prevent poisonous foods
from ending up on our shelves. So, the
FDA, oh no, it's terrible organization.
But in some ways, you know, I I can
safely go to the market now, buy
anything, and not be afraid of my life,
right?
>> Stay away from the lettuce.
>> Yeah. You know, it's probably a good
time to buy Taco Bell stock is all I
could [laughter] say.
Okay, we're really at the end of our
time and I wanted to give you an
opportunity to speak on behalf of Cypac.
Why are you interested in this? Uh why
are you, you know, communicating with
the media? Why are you coming on and
talking about this in in the television
media and here on Think Tech? What
interests you about it? And why should
people call you up on the phone and ask
you about it? Ask you for protection
against these things that are supposed
to protect us. uh because it's a really
interesting double standard, if you
will, a double concentration of capital
standard uh that you you you want
protection, but you want protection
against those who are claiming to want
protection. I'm getting confused
already. So, what is your advice? What
are your parting words to our to our
audience?
>> Look, it's really simple. At CIPAC, we
are community defenders. Everyone who's
here does the best that they can to keep
our community safe.
Now, most of our community is a business
community, and if you're an individual,
guess what? You probably work somewhere,
and that business needs protection. So,
our mission is to keep businesses safe
here in uh in Hawaii because uh that's
what keeps our island alive. Uh we're
under constant threat from cyber
attacks. Uh we are the gateway uh to
Asia and a lot of stuff comes out of
Asia. you know, we do have to do our
best to prevent a disaster from
occurring. We have a very high uh, you
know, highly visible military presence
here. So, we also have a target on our
back. And, uh, you do need someone with
some experience in helping you protect
your business from having that kind of
thing happen to you. And so, that's why
we've been doing this for many years
now, almost 20 years here. So, uh, you
know, we we just appreciate any
opportunity we can to help spread the
word about what's going on in the world
of technology and, uh, if your business
can use some protection, this is why
we're here. And of course, uh, all kinds
of things happen in the news that are
not related to your business protection,
such as these ALPR cameras. Uh but we
want to help uh you know be a source for
awareness uh that we are the we are the
defenders and we're we're hopefully the
white knight that you turn to whenever
there is an issue and if we can help
we'll do our best and uh if you're
definitely a business we'll do our best
to prevent it from happening to you.
>> That's great. Thank you for telling us
about that. It sounds to me like this
surveillance business falls really in
the same bucket that you've been talking
about, the hacking business um for a
long time and it's like it's like an
invasion of our private space the way
all those other things are an invasion
of our private space. So good for you
for following it. Well, let's leave it
there. Thank you so much to our guest
Atilliso Cypac. I'm Jay Fidel, host of
ThinkTech Tech Talks. The title of this
episode has been AI based street
surveillance in Hawaii and elsewhere.
Thanks to our viewers for watching.
We'll see you again soon for the next
one. Aloha.
>> Aloha.
>> [music]