
Posted Zero Hedge
As the headquarters to the U.S. military, the Pentagon is surrounded by billions of dollars worth of surveillance and security technology. These systems provide multiple layers of protection for the building but they also carry a risk of backfiring: any surveillance system that is vulnerable to intruders could potentially provide unauthorized users with details about the activities of the Defense Department (DOD) and its employees. This risk is higher than usual right now because of the decision to install a controversial piece of equipment all over the Pentagon grounds: Flock cameras.
There are at least nine Flock automated license plate readers (ALPRs) currently monitoring the traffic lanes used by drivers entering the Pentagon's parking lots, including many of the DOD's own employees. The purpose of these cameras is to give the Pentagon's security forces the ability to automatically record information about incoming vehicles that may pose a security risk. But if the alleged vulnerabilities of Flock cameras are as serious as the company's critics allege, then this equipment could be exploited to obtain a detailed list of the national security officials seen entering the Pentagon each day. In this way, the Pentagon's rush to obtain security equipment from private contractors may pose a national security risk of its own.
Concerns about the ability of Flock products to track people alongside cars has produced backlash from privacy-minded citizens, resulting in both protests and contract cancellations. Others have criticized Flock's devices for security vulnerabilities that expose them to unauthorized users, flaws which could be especially dangerous in the context of military facilities. Flock Safety has sought to downplay these issues, insisting that they have "never been hacked." Critics dispute this claim, pointing to multiple different ways that Flock's devices can be accessed by unauthorized users.
These concerns prompted two members of Congress' Intelligence committees — Senator Ron Wyden (D-Ore.) and Rep. Raja Krishnamoorthi (D-Ill.) — to write a letter last year asking for an investigation into Flock's "negligent cybersecurity practices." The duo alleged that the company "needlessly exposes Americans to the threat of hackers and foreign spies tapping this data." When asked about the Pentagon's Flock cameras, Sen. Wyden said that "Installing internet-connected cameras in the Pentagon parking lot is obviously a dumb idea. In particular, given Flock's troubling cybersecurity track record, the Pentagon might as well send the data from those cameras directly to China, Russia and Iran."
Under The Radar
In late 2021, the Defense Department issued a contract to the Virginia-based company M.C. Dean Inc. to improve the Pentagon's "electronic and physical security systems." This agreement is an "Indefinite Delivery / Indefinite Quantity" contract, which allows the DOD to issue mini-contracts known as "delivery orders" directly to their chosen contractor whenever new needs arise. While the DOD has no direct relationship with Flock Safety, it acquired the company's products through these delivery orders.
In May 2023, the DOD issued a delivery order to M.C. Dean indicating its interest in a "license plate recognition system" specified as "for the entire Pentagon reservation parking facilities." In September, a new order was issued to "procure Flock perimeter license plate reader systems." Because this decision came through the order of a pre-existing contract, neither Flock Safety nor its resellers had to participate in a competitive bidding process to prove that their products were the best prepared to meet the Pentagon's needs — or that they had the most secure system available.
It is unclear who decided that the Pentagon should acquire its system from Flock. The Defense Department requested Flock products in its September order, but it may have done so under advisement from M.C. Dean or the various subcontractors that it worked with. Neither the DOD, M.C. Dean, nor any of the subcontractors involved in this process responded to a request for comment.
The Flock Spreads
Flock Safety's license plate readers have come under fire from multiple cybersecurity experts. One such critic, hacker and researcher Jon Gaines, has argued that some of the company's technology can be breached in "about 30 seconds." Reached for comment, Gaines said that he "absolutely" considers the Pentagon's Flock cameras to be a potential security risk. Asked whether it was possible for the DOD to have modified the devices to address their security flaws, he replied: "No, by design the customer, in this case the Pentagon, have no control or insight into the security posture or control of the physical devices deployed by Flock."
The DOD distributes parking permits to employees working at the Pentagon, meaning that it already knows who uses its parking lots. The real value of the ALPR system is its ability to document unknown drivers. But if this data were accessed by an unauthorized user, they could use it to compile a list of active DOD employees and their daily schedules. The PFPA considers it a priority to prevent the public from accessing this type of information — yet by engaging in this exact behavior with cameras that allegedly suffer from serious vulnerabilities, the Pentagon's security force could potentially be creating one of their own worst-case scenarios.
Data-sharing poses yet another risk. Technically, the Flock system would not even need to be "hacked" for its data to be dangerous: all it would take is for one person with access to the system to misuse it or share it with others in an unauthorized way. The Institute for Justice maintains a growing database of more than 200 incidents in which Flock cameras have been used for reasons other than their intended purpose.
The DOD has not disclosed everyone who has access to the data gathered by its license plate readers. It is even possible that Flock Safety itself has some level of access to the Pentagon's data. Flock Safety did not respond to a request for comment.
Authored by Brett Heinz via Responsible Statecraft


















