Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Surveillance topic
No spam. Unsubscribe anytime.
Residents and security expert raise privacy and security concerns about Ridgecrest's vehicle-surveillance cameras
Summary
At the Nov. 19 meeting, resident Mike Licitra presented a white paper alleging serious security flaws and broad data collection by the city's vehicle-surveillance cameras, prompting council members to request follow-up; callers also urged review of access, retention and authorization practices.
Get email alerts on the Surveillance topic
No spam. Unsubscribe anytime.
At the start of public comment on Nov. 19, resident Mike Licitra told the Ridgecrest City Council that the city's fleet of vehicle-surveillance cameras captures thousands of images daily, uses automated algorithms to extract license-plate and vehicle details, and stores data in a cloud system with retention "typically 30 days, but as long as 1 year in some cases." He presented a white paper prepared by an information-security researcher and listed device and platform vulnerabilities he said leave the system susceptible to compromise.
Licitra described multiple technical failures he characterized as serious: the cameras run an Android build discontinued in 2021; researchers documented hundreds of vulnerabilities; a sequence of button presses can enable a shell with root privileges on the device; Android Debug Bridge (ADB) on the cameras was described as not requiring authentication; internal storage was said to be unencrypted; and the devices can fall back to stored Wi-Fi networks if cellular service is interrupted, which Licitra said could allow interception of data. He said cloud access does not uniformly require two-factor authentication and that city search logs often show uninformative reason codes.
Several callers echoed privacy concerns. Mike Neil (caller) said he objects to being photographed repeatedly at multiple camera locations in town and urged the council to consider those concerns. Councilmember Gorman asked staff and council decision-makers to review the white paper and pursue remediation with the vendor, and encouraged officials to meet with the commenter and the material supplied.
Councilmembers acknowledged the seriousness of the technical claims and directed staff to follow up: at least one councilmember asked the person responsible for the camera deployment to examine security gaps and report back. No formal policy action or suspension of the system was recorded during the meeting.
What was not resolved in the meeting: the city did not present a technical response to the researcher's claims, the record did not include the vendor's written security assessment or the current data-retention policy in full, and the council did not adopt an immediate moratorium or new access controls during the session. Councilmembers asked staff to investigate and to consult with the commenter and vendor, and callers requested public disclosure of system logs and policy details.

