Today in Surveillance:

  • Flock ran an internal webinar training police to monitor No Kings protests with ALPRs, drones, and FlockOS. Director of market management Caity Peak walked incident commanders through the same tools Flock tells the public are reserved for the worst crimes, including Flock Nova's LPR-plus-credit-header searches and FlockOS's "single pane of glass" combining cameras, drones, gunshot detectors, and 911 data. The training used a No Kings protest in Denver as a worked example [1][2].
  • The FBI is probing a dark-web service called Nexus that posted more than 153 million driver's-license scans. KrebsOnSecurity reporter Brian Krebs found his own license among the advertised data and traced the source to identity-verification vendor idscan. USA Today and TIME confirmed the FBI investigation on September 3 and 6 [3][4][5].
  • England's Children's Commissioner told Parliament the Online Safety Act has made "absolutely no difference" to children's online safety. Dame Rachel de Souza told the Lords Communications and Digital Committee she is "furious" with Ofcom, said the regulator is "reacting to harms rather than anticipating them," and called for "some big fines" [6][7].
  • EFF will appeal a federal court ruling that let a public-access TV station DMCA a citizen-journalism account on a subjective good-faith belief. The court found Section 512(f) of the DMCA does not require "a perfect or even reasonable fair use analysis," a standard EFF argues turns the statute into a box-checking exercise that chills critical speech [8].
  • Comcast's WiFi Motion turns the home router into a motion sensor and Comcast can share that data in connection with law enforcement investigations. The feature lets Xfinity users set home, asleep, and away modes and view live motion activity through the Xfinity app [9].
  • Simon Weckert's "digital camouflage" shirt defeats the same AI object-recognition systems now used by police outside Berlin. 404 Media reported the button-down disrupts person-detection and anomaly detection on the cameras at Kotbusser Tor. Bruce Schneier tagged it as a counter-surveillance case in waiting [10][11].
  • AI coding agents from Anthropic, OpenAI, and Nous are installing unknown and unowned packages from open registries. Researchers who registered a handful of abandoned names hosted in vendor `llms.txt` files received "phone-home" beacons from a Fortune 500 company within an hour. Schneier framed it as a Solar-Winds-style supply-chain hole [12][13].

Also today: The Register reported that attackers hit fishing-app Fishbrain and made off with crackable password hashes alongside names, emails, phone numbers, birth dates, and usernames; Fishbrain reset affected passwords [14]. EFF's September 3 write-up on Texas Governor Greg Abbott's August 28 ban on state-agency spending on Flock cameras and the Florida Department of Transportation's August 31 bulletin eom26-01 ordering ALPRs off state highway right-of-way within 30 days continued to draw readers as the Axon redesign conversation out of the August 26 "From backlash to trust" webinar rolled forward [15][16].

Flock Trained Police to Monitor No Kings Protesters

404 Media on September 3 published a recording and transcript of a Flock Safety internal webinar, titled "Prepared for Anything: How Cities Prepare for Planned and Unplanned Events," in which Flock's director of market management, Caity Peak, walked police incident commanders through how to use Flock's commercial stack to monitor political demonstrations, parades, and bike races. The training is the strongest documented case yet of Flock teaching officers to use its tools in exactly the way its public posture denies, and lands inside the same arc our September 3 briefing tracked on the Texas and Florida pullback from Flock cameras [1].

The worked example is a No Kings protest in Denver. Peak walks the audience through a FlockOS dashboard layered with live video feeds, traffic data, response plans, floor plans of nearby buildings, and indoor cameras, then demos Flock Nova (LPR plus "person data, IP data, email data, sex offender data, license plate data, vehicle data, and OSINT") and Flock's free-form search, marketed as an "AI-powered video search and alerts" engine that "works like a Google Search." The political-protest instruction is explicit. Peak tells the audience to set up cameras at intersections "where we see the most events, and then I hoped that if an event happened in front of a camera, it's one that's in an intersection where I chose to put [the ALPR] and not one where I chose not to put an ALPR." A separate Sacramento car-sideshow example layered drones, cameras, ALPRs, and social-media monitoring into a single picture, with a "THINGS TO LOOK FOR" list of mismatched front and rear wheels, car-club stickers, and license plates covered with car-club logos [1].

The gap between Flock's public stance and the training is the story. The company has told audiences that ALPR cameras take "only static images at a single place and time" and are used primarily to solve the worst crimes. The webinar describes a continuous, multi-sensor surveillance environment built around planned political demonstrations. The New Orleans real-time crime center, run by Ross Bourgeois with former New Orleans Police Department officer and current Flock employee Matt Patin, shared "7 terabytes of information" with DHS, HSI, the FBI, and federal fusion centers after the January 1, 2025 Bourbon Street attack that killed 14 people. 404 Media reports that more than 4,800 cities run FlockOS software, the scale the new training video is being delivered into [1].

FBI Probes Dark-Web Service Selling 153M Driver's Licenses

The KrebsOnSecurity story opened a federal investigation into a dark-web service called Nexus that advertised more than 153 million driver's-license scans of people in the United States and Canada, plus millions of additional identity and medical cards. Brian Krebs, the journalist who broke the story, found his own driver's license among the advertised data. Krebs traced the source to idscan, an identity-verification vendor that handles KYC scans for other businesses. USA Today confirmed on September 6 that the FBI had opened an investigation into the source of the breach and the operation of the dark-web service. FreightWaves raised the specific concern that commercial driver's licenses sit in the data, which is a direct hit on trucking and freight security [3][4][5].

The surveillance reading is that the driver's-license scan was already a surveillance artifact before the breach. Every company that uses idscan for KYC is, in effect, building a national face-and-license database one upload at a time. The pattern repeats: a single KYC vendor aggregates scans from every customer that uses its service, and one breach turns those scans into a turnkey identity kit for the attacker economy. The deeper question is whether the KYC pipeline itself is the problem: every vendor that asks a user to upload a scan of a government ID for an age check, a financial onboarding, or a platform account is contributing to the same pool [3][4].

UK Children's Commissioner: Online Safety Act "Absolutely No Difference"

England's Children's Commissioner, Dame Rachel de Souza, told the House of Lords Communications and Digital Committee on September 3 that the Online Safety Act has made "absolutely no difference" to children's online safety and that she is "furious" with regulator Ofcom for not using the powers it already has. The Register's Connor Jones reported the hearing the same day. The Act's key child-protection duties took effect more than a year before the hearing [6].

De Souza told the Committee she was "really cross" there is no hard evidence the OSA changed how platforms operate, that the Act had "not been flexible enough" and had not "kept up with the time," and that she could not see the risk assessments platforms had submitted. "If we cannot even see the risk assessments," she said, "how on earth can we judge the efficacy of it?" She called for Ofcom to "use its teeth," "use all their powers," and impose "some big fines," and said the regulator was "reacting to harms rather than anticipating them." Ofcom responded by pointing to Section 393(1) of the Communications Act 2003, which restricts the regulator's disclosure of platform risk assessments, and to its December risk-assessment analysis publication. The Committee asked Ofcom about its single notable enforcement action, an investigation into X over Grok "nudifying" concerns [6][7].

The structural angle is the same one the UK Cyber Security and Resilience Bill story raised on the AI-vendor side. The UK is choosing to regulate the platform or service that touches the end user, while leaving the model vendor or the underlying capability under voluntary commitments. The Children's Commissioner testimony is the first public, on-the-record evidence from a senior statutory officeholder that the platform-side hook has not produced the child-safety outcome the Act promised [6].

EFF Will Appeal the DMCA Ruling Against Citizen Journalists

EFF said on September 3 that it will appeal to the First Circuit a decision by a federal court in Massachusetts that let a public-access TV station DMCA a citizen-journalism YouTube account on a subjective good-faith belief. The case is Channel 781 News versus Waltham Community Access Corporation (WCAC). Channel 781 is a volunteer citizen-journalism group that posted short newsworthy excerpts from recordings of Waltham city government meetings that WCAC had produced; in September 2023, WCAC sent three copyright takedown notices to YouTube targeting fifteen of Channel 781's videos, and YouTube removed them and, under its three-strikes policy, temporarily disabled Channel 781's entire account just days before a local election [8].

Channel 781 sued WCAC under Section 512(f) of the DMCA. The court ruled that a subjective good-faith belief is sufficient to shield a copyright holder from Section 512(f) liability, even if that belief is unreasonable. The opinion stated that Section 512(f) does not require "a perfect or even reasonable fair use analysis." The court wrote that WCAC's fair use analysis "may have been deficient" but concluded it could not reject WCAC's professed belief even though the court itself "would have reached the opposite conclusion" on fair use [8].

EFF's appellate argument is that, if a copyright holder can avoid liability despite a "cursory, incomplete, and objectively unreasonable analysis that ignores important facts, even when there's evidence that the copyright holder wanted to suppress critical speech, the obligation to consider fair use risks becoming little more than a box-checking exercise." The record includes evidence that WCAC's Chris Wangler did not consider several facts relevant to fair use, that Channel 781 used relatively small portions of WCAC's recordings, and that WCAC sent the takedowns during a local election shortly after Channel 781 posted a campaign statement by Waltham's mayor that WCAC had mistakenly made available online. The court found WCAC objected to its footage being used to criticize local officials and advance political viewpoints [8].

The surveillance reading is the chilling effect. Citizen journalism on local government is an accountability mechanism that public bodies cannot easily suppress without consequence. A Section 512(f) standard that protects a copyright holder who subjectively believes a takedown is correct, regardless of how unreasonable that belief is, hands any public entity that controls meeting recordings a frictionless tool for removing critical coverage during the news cycle that matters most [8].

Comcast's WiFi Motion Turns the Home Router Into a Motion Sensor

Bruce Schneier pointed readers on September 2 to a Gizmodo report on Comcast's WiFi Motion, a feature in the Xfinity app that turns the ISP-supplied wireless router into an in-home motion detector. The feature sends push notifications when motion is detected near connected devices such as a TV or printer, offers different settings for when people are home, asleep, or away, and lets users view live motion activity through the Xfinity app. The motion information is generated by WiFi signals in the home [9].

Per Comcast's support page, information generated by WiFi Motion may be shared with third parties in connection with law enforcement investigations or proceedings, disputes Comcast is a party to, and court orders or subpoenas. Schneier's framing was short: "Sounds like a great surveillance tool." The deeper point for non-technical readers is that the Xfinity router is no longer just an internet gateway; it is an in-home sensor platform, and the law-enforcement data-sharing clause is in the operator's standard legal terms. The mitigation paths Schneier readers flagged in the comments include using your own DOCSIS-compliant cable modem and disabling the ISP-supplied WiFi, building a "Garden Path" two-router design with RX-only instrumentation taps, and using PCs running open-source software instead of edge network devices [9].

Simon Weckert's Digital Camouflage Shirt Defeats AI Police Cameras

404 Media reported on September 1 that artist Simon Weckert built a button-down shirt patterned with "flowery, blurry globs of green and pink" that, when held in front of a person, causes AI object-detection to drop its bounding box and "PERSON" label; removing the shirt makes detection return. 404 describes the disruption at the person-detection layer; vendors in the same camera class (404 references Avidbeam's marketing material) market separate anomaly-detection features that flag behaviors like loitering, fighting, lying down, or abandoned packages. The deployment context is the AI object-recognition cameras recently put into service by police at Kotbusser Tor, a Berlin subway stop. 404 also references BVG's separate plan to expand AI surveillance cameras across the network, but the Kotbusser Tor deployment in the article is the police-run one, not a BVG-operated system [10][11].

Weckert's quote connects the technical demo to the surveillance reading. "Obviously people don't like it because it means that AI is tracking the movements and behaviors of people," he told 404 Media. "It can detect if somebody's laying on the ground so that means homeless people could be detected and police get triggered." The same AI pitched as a public-safety tool gives police a continuous read on whether someone is homeless, loitering, or "anomalous" enough to dispatch a response. The shirt is not a magic cloak: it disrupts detection at the bounding-box level, which means a determined operator with the right camera angle can still recover the target. What it does is raise the cost of reliable detection, the same cost-raising effect that has driven the Flock takedown arc [10].

AI Coding Agents Install Unknown Code From Vendor Docs

Schneier on Security on September 2 linked an Ars Technica investigation that scanned 6,214 live domains belonging to defense contractors, Fortune 500 companies, and Big Tech firms for `llms.txt` and `llms-full.txt` files. The scan found 8,265 such files across those domains. Researchers identified 120 files on different sites that pointed to unregistered code packages or domain names. They registered a handful of the unclaimed names and hosted beacon packages; within one hour they received a "phone-home" response from a Fortune 500 company, and a few dozen more from Fortune 500 firms and startups over the following days. None of Anthropic, OpenAI, or Nous Research, whose coding agents were identified in the scan, responded to Ars Technica's requests for comment [12][13].

Coding agents from Anthropic (Claude), OpenAI (Codex), and Nous Research (Hermes) treat vendor `llms.txt` documentation as ground truth and follow documentation links to install packages without verifying ownership. The risk is not prompt injection; the risk is that the instruction is benign and comes from a legitimate source, and the danger comes later when the package or domain it points to is abandoned and someone else claims it. Researcher Alon Hertz: "The trust model is broken. Agents treat vendor docs as ground truth and don't question them, and neither do the humans supervising them." Schneier framed the failure mode as a Solar-Winds-style supply-chain hole, where a single compromised dependency cascades through every downstream user, except here the dependency was never malicious to begin with, just abandoned [12][13].

What to Watch

Whether the 404 Media training video triggers procurement action. Flock's webinar is the most explicit training-on-political-protest documentation the public has seen from the company. Watch for city council resolutions, contract non-renewals, or attorney-general letters that cite the training specifically, the way the Texas and Florida pullback cited prior misuse [1].

The FBI Nexus probe and the idscan attribution. Krebs traced the source to identity-verification vendor idscan. Watch for a search warrant, a sealed indictment, or an FBI flash alert that confirms the source and the date range of the breach, and for the first company to publicly disclose that it was an idscan customer [3][5].

Ofcom's response to the Children's Commissioner. De Souza called for "some big fines" and for Ofcom to "use its teeth." Watch the next enforcement notice and the next quarterly report for evidence the regulator has changed its posture. The Meta $18B US settlement, which would impose two-hour daily limits for under-16 users on Facebook and Instagram, prompts against endless scrolling, and restrictions during school hours and at night, is also a measure of the UK regulatory baseline Ofcom is being measured against [6][7].

The First Circuit appeal in Channel 781 v. WCAC. The district court's "subjective belief" standard for Section 512(f) is the highest-stakes DMCA precedent on citizen journalism since Lenz v. Universal. Watch for EFF's opening brief and for any amicus filings from public-access TV associations or press-freedom groups [8].

Whether Comcast expands WiFi Motion or narrows it. Comcast's support page admits the data may be shared in connection with law enforcement investigations or proceedings. Watch the next Xfinity app release for a granular opt-out, the next Comcast privacy-policy update for any change to the data-sharing language, and the first reported law-enforcement subpoena served on WiFi Motion data [9].

The `llms.txt` standard response. The 120 unregistered packages and domains were not malicious at the time of writing. Watch whether the `llms.txt` specification site adds a verification requirement, whether the major agent vendors (Anthropic, OpenAI, Nous) publish their first guidance on package-name ownership checks, and whether the Fortune 500 firms that received beacons publicly disclose the incident [12][13].

Sources

  1. 404 Media, Jason Koebler: Flock Taught Cops How to Surveil No Kings Protesters (September 3, 2026; the "Prepared for Anything" webinar recording and transcript, Caity Peak's quotes on No Kings protests and intersection-level ALPR placement, the Denver and Sacramento worked examples, the Flock Nova and FlockOS demo, the New Orleans Bourbon Street attack data-sharing figure, the 4,800-cities FlockOS figure, and the prior EFF and 404 Media No Kings reporting). https://www.404media.co/flock-taught-cops-how-to-surveil-no-kings-protesters/
  2. State of Surveillance: Daily Surveillance Briefing, September 3, 2026: Two States vs Flock (the prior briefing that tracked the Abbott ban, the FDOT bulletin eom26-01, and the broader Flock pullback arc the No Kings training extends). /news/daily-surveillance-briefing-september-3-2026
  3. KrebsOnSecurity, Brian Krebs: FBI Probes Service Selling 153M+ Drivers Licenses (September 2026; the original Nexus dark-web reporting, the 153M driver's-license scan figure, the idscan attribution, and Krebs finding his own license in the advertised data). https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
  4. TIME: FBI Probes Possible Dark Web Sale of Over 153 Million Driver's License Scans (September 3, 2026; confirmation of the FBI investigation into the source of the breach and the dark-web service). https://time.com/article/2026/09/03/fbi-probes-reported-dark-web-drivers-license-breach/
  5. USA Today: FBI investigates dark web sale of driver licenses (September 6, 2026; the September 6 confirmation of the FBI probe, the New Orleans cyber-firm context, and the CDL security concerns). https://www.usatoday.com/story/news/nation/2026/09/06/drivers-license-data-breach-fbi/91642409007/
  6. The Register, Connor Jones: UK's Online Safety Act has made 'absolutely no difference,' kids say (September 3, 2026; Dame Rachel de Souza's testimony to the House of Lords Communications and Digital Committee, the "absolutely no difference" quote, the "furious" quote, the "use its teeth" and "some big fines" quotes, the Ofcom response on Section 393(1) of the Communications Act 2003, and the Grok "nudifying" investigation). https://www.theregister.com/security/2026/09/03/uks-online-safety-act-has-made-absolutely-no-difference-kids-say/5293893
  7. State of Surveillance: Daily Surveillance Briefing, September 3, 2026: Two States vs Flock (the prior day's note on the UK Cyber Security and Resilience Bill and the voluntary AI Cyber Security Code of Practice, the same UK "regulate the operator, not the vendor" pattern the de Souza testimony extends). /news/daily-surveillance-briefing-september-3-2026
  8. EFF Deeplinks, Betty Gedlu: Court Rules Against Citizen Journalists in DMCA Takedown Case, EFF Will Appeal (September 3, 2026; the Channel 781 v. WCAC facts, the September 2023 takedown notices, the Section 512(f) ruling, the "perfect or even reasonable fair use analysis" quote, the election-cycle timing, and the First Circuit appeal). https://www.eff.org/deeplinks/2026/09/court-rules-against-citizen-journalists-dmca-takedown-case-eff-will-appeal
  9. Schneier on Security: Wireless Routers as Motion Detectors (September 2, 2026; the Gizmodo source on Comcast WiFi Motion, the Xfinity app integration, the home/asleep/away modes, the law-enforcement and subpoena data-sharing language, and the Schneier "great surveillance tool" framing). https://www.schneier.com/blog/archives/2026/09/wireless-routers-as-motion-detectors.html
  10. 404 Media, Jason Koebler: "Digital Camouflage" Shirt Confuses AI-Powered Surveillance Cameras (September 1, 2026; Simon Weckert's shirt design, the bounding-box and "PERSON" label disruption, the Kotbusser Tor / BVG deployment context, the Avidbeam anomaly-detection vendor reference, and the Weckert quote on homeless-person detection). https://www.404media.co/this-digital-camouflage-shirt-confuses-ai-powered-surveillance-cameras/
  11. State of Surveillance: Digital Camouflage Shirt Confuses AI Cameras (the dedicated State of Surveillance brief on the Weckert shirt and the broader counter-surveillance stack). /news/digital-camouflage-shirt-berlin-police-ai-cameras-2026
  12. Schneier on Security: AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks (September 2, 2026; the 6,214-domain scan, the 8,265 `llms.txt` and `llms-full.txt` files, the 120 unregistered packages and domains, the within-one-hour Fortune 500 beacon, the Anthropic, OpenAI, and Nous Research agent identification, and the Hertz "trust model is broken" quote). https://www.schneier.com/blog/archives/2026/09/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate-networks.html
  13. State of Surveillance: AI Coding Agents Supply Chain Risk (the State of Surveillance brief on the supply-chain risk and the Solar-Winds analogy). /news/trapdoor-supply-chain-attack-ai-coding-assistant-poisoning-claude-cursor-2026
  14. The Register: Cybercrooks trawl Fishbrain to net password hashes (September 3, 2026; the Fishbrain password-hash and salt theft, the names, emails, phone numbers, birth dates, and usernames exposure, and the Fishbrain forced password reset). https://www.theregister.com/cyber-crime/2026/09/03/cybercrooks-trawl-fishbrain-to-net-password-hashes/5294158
  15. EFF Deeplinks, Rindala Alajaji and Adam Schwartz: Texas and Florida Step Back from ALPRs (September 3, 2026; the August 28 Abbott ban on state-agency Flock spending and the August 31 FDOT bulletin eom26-01 ALPR removal order the new Flock training story now sits on top of). https://www.eff.org/deeplinks/2026/09/texas-and-florida-step-back-alprs
  16. State of Surveillance: Flock Cameras Destroyed Nationwide in ICE Backlash (the standing coverage of the Flock cancel wave and the warrant-requirement debate that the new training-video reporting extends). /news/flock-cameras-destroyed-nationwide-ice-backlash-2026