Most of this site is about people with power over Asheville’s surveillance system. This page is about someone with none: an outside researcher who studied these cameras on his own time and came here to help residents understand them. Benn Jordan appeared at a CAMS surveillance event in Asheville on May 25, 2026, doing a public Q&A alongside Kim Roney. His work is the clearest available explanation of two things Asheville officials rarely address: what these systems can do, and how badly built they are.

His findings are worth knowing because they’re independently confirmed. When a company’s own contractor or a paid consultant makes a claim, you weigh the source. Jordan is a musician (recording as The Flashbulb) who turned his technology YouTube channel (over a million subscribers) toward surveillance investigation, works with named security researchers, and offered Flock supervised access to verify his findings. Where his work is cited below, national outlets reproduced it independently.

What he found about Flock cameras

The cameras were left streaming to the open internet. In December 2025, Jordan found dozens of Flock’s “Condor” pan-tilt-zoom cameras (the kind that track people, not just plates) reachable through a normal internet-of-things search engine, with no password. Anyone could watch the live feeds, pull about 30 days of archived footage, change settings, or delete video. This is his best-corroborated work: 404 Media reproduced it independently, watching themselves in real time through an exposed camera at a California intersection (404 Media), and local stations in Colorado, Iowa, and Florida confirmed exposed cameras in their own areas. Flock called it “a limited misconfiguration” it had since fixed.

To be precise about what this was: the cameras were left publicly accessible, not broken into. That’s arguably worse: no attacker skill was required. It bears directly on the promise Asheville residents were given. At the April 28 vendor session, the Flock representative said the company’s cloud “has never been hacked. It has never been breached.” Whether or not that specific claim is technically defensible, the surveillance footage was exposed anyway, through ordinary misconfiguration. The security that matters to a resident is whether their image ends up on the open internet, and it did, elsewhere, weeks before Asheville voted. (The National Wave tracks the broader security record.)

The devices themselves are fragile. In a November 2025 investigation with security researcher Jon Gaines, Jordan demonstrated gaining root access to a Flock camera in seconds through a physical button sequence, and documented that the units ran a discontinued version of Android with hundreds of known vulnerabilities. He has said the two of them catalogued more than 70 vulnerabilities across the ecosystem (Privacy Guides). This is a single research team’s account rather than an independent audit, but it is specific, on the record, and was met with a Flock response rather than a denial that it happened.

Their own effectiveness numbers come from the company. Jordan’s reporting notes that Flock’s widely repeated claim about solving a share of crime traces to a paper written by Flock employees, and that crime fell nationally in places with and without the cameras. That’s the same problem this site documents in Asheville, where the crime figures used to sell the RTIC shifted and didn’t hold up.

What he says about home cameras

Jordan’s April 2026 video “It’s Time to Take Down your Smart Cameras” is the video I send people first, because it makes a hard argument clearly: in today’s landscape, a home surveillance camera is often not in your own interest. Jordan’s case, in plain terms:

  • Your camera becomes someone else’s evidence. Cloud cameras like Ring are wired into law-enforcement and insurance workflows. Footage you recorded for your own safety can create obligations for you (to preserve it, to hand it over) and can be used in ways you didn’t intend.
  • The devices are insecure in the same family of ways the Flock cameras were.
  • They don’t deliver the safety they promise. Jordan cites research finding no significant crime-deterrence effect from smart cameras.
  • His prescription: local storage that you control and no one else can reach, or no camera at all. He says he returned his own Ring devices.

This is contested (the security-camera industry publication IPVM published a rebuttal) and you should watch the video and weigh it yourself. But it connects directly to Asheville: every privately owned camera that a business or landlord opts into the police network is a camera whose owner may not have thought through whose evidence it becomes.

Watch his work

  • “This Flock Camera Leak is like Netflix For Stalkers” (Dec 22, 2025): the exposed-cameras finding · video
  • “We Hacked Flock Safety Cameras in under 30 Seconds” (Nov 16, 2025): the device-security investigation · video
  • “It’s Time to Take Down your Smart Cameras” (Apr 2, 2026): the home-camera argument · video
  • “Breaking The Creepy AI in Police Cameras” (Aug 26, 2025): how plate readers work, built from scratch for ~$250 · video

A note on accuracy: this page describes Jordan’s findings as he and independent outlets reported them. The exposed Condor cameras were reachable on the open internet, not broken into. His plate-reader “defense sticker” is a demonstrated proof-of-concept against the software, not a proven or necessarily legal street countermeasure. I found no recording of his Asheville Q&A, so nothing here attributes an Asheville-RTIC-specific statement to him.

Related: Before You Plug In · The National Wave · Get Involved · Their Claims vs The Record. Last updated: Aug 17, 2026.