TECH ‘Adversarial clothing’: are garments designed to confuse facial recognition systems about to go mainstream?

Blacknarwhal

Three-Time Trump Voter
I didn't even know this was a thing until just now.

Fair use cited so on and so forth.


‘Adversarial clothing’: are garments designed to confuse facial recognition systems about to go mainstream?​


Amelia Hill

5–6 minutes



As facial recognition technology is rolled out across Britain’s public spaces, a new generation of designers say privacy could be the next big fashion trend.

Companies have started incorporating “adversarial patterns” in their garments – carefully designed arrangements of shapes, colours and repeated motifs said to exploit weaknesses in some computer vision systems.

The designers say advances in computing have made it easier to incorporate such patterns into commercially viable garments. Experts caution that the effectiveness of the patterns depends on the surveillance system and the conditions in which it is used, but Nick Tidball, the co-founder of the clothing brand Vollebak, thinks “adversarial clothing” could be on the cusp of going mainstream.

“Anti-surveillance feelings are so widespread that all it would take is for a single celebrity to wear one of these garments, currently popular in the countercultural fashion world, to a high-profile event for it to take off,” he said.


“So-called ‘adversarial clothing’ wins on many levels. As well as the practicality of protection, it’s fashionable and fun, it makes a powerful, public statement that many are in agreement with, it spreads even more awareness about the importance of privacy and it helps encourage public debate.”

Unlike traditional CCTV, modern computer vision systems can identify faces, follow individuals across cameras and search footage at scale.
Recent advances in generative AI have made this type of automated identification cheaper and more widely available to police, retailers and private businesses, an expansion recently warned against by Britain’s biometrics watchdogs, which have called for more laws and a regulator to clamp down on misuse.

Evidence of misuse and that black and Asian people are more likely to be incorrectly identified than white people has led to increasing public concern. A recent poll showed almost 60% of people believed facial recognition was “another step towards turning the UK into a surveillance society”.

Dr Jennifer Bell, a senior lecturer specialising in creative AI, fashion and digital culture at Nottingham School of Art & Design, said clothing with anti-facial recognition designs was increasingly available at high street prices and was being marketed to a wide demographic. “That growing awareness combined with a lowering of cost often precedes the tipping point towards a real cultural moment,” she said.
Daniel Preuß, the co-founder of the Urban Privacy clothing brand, said new technology meant you could now “combine smart, striking style with invisible protection”.

He emphasised that because surveillance systems are so powerful, no design can guarantee security from detection, but said “the added value of fashion is to spread awareness and help propagate public discourse”.

Preuß said his designs used large-scale prints, asymmetrical cuts and streetwear-inspired silhouettes to confuse facial recognition algorithms. The company said its Urban Ghost coat integrates LEDs into the hood that emit infrared light to dazzle night-vision surveillance cameras.

Preuß, who co-founded his company after reading about the whistleblower Edward Snowden’s revelations about US surveillance in the Guardian, said his designs played with the fact that “facial recognition systems freak out when they see multiple faces at once”.

“Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,” he said.
Bell, however, said “none of these products are tried and tested, and a lot of these surveillance technologies can deal with a little resistance … [but] even if the designs don’t necessarily work perfectly, fashion is also a visible sign of resistance.
“This is consumers collectively coming together to make a visible statement.”

Rachele Didero, the founder of Cap_able, which creates clothing marketed as making AI recognition more difficult, said interest in her brand had rocketed in the last few years. “When I started doing this in 2018, people thought I was designing masks to rob banks,” she said.

“But now these concerns are no longer niche. New generations are increasingly afraid of AI and concerned for their privacy,” she said. “Those wearing these products are the vanguard. The mainstream is quickly coming up behind them, helped by the fact that bigger companies will see the potential for profit and will push the trend into the popular, public domain, changing the way we dress on a large scale.”

Tidball, however, said that whether anti-surveillance fashion became mainstream may ultimately depend less on designers than on governments. “If such clothing genuinely proved effective, it could get political very quickly,” he said. “Then this type of clothing could find itself banned.”
 
They missed the facial recognition part with their tops and pants.
And the gait analysis, body type analysis, electronic signals collection etc.

But I will say, every little bit helps. Get you some of this clothing, a hat with IR lights, IR reflective sunglasses, no phone, facial mask, and mess up your gait, and your on to something.

You’re also now a “terrorist”, but definitely on to something.
 
Only 60%.... but then again,

Few realize a total police state in a one world government framework is the plan. Few realize this, even in America. I find it insane the liberal left, which is the communist left, is willing to voluntarily give up their freedom so willingly....at such a cheap price...when so many have died to stop from being in chains. Those in the know, know the true value of freedom, and no man or machine has the right to take it away. Natural rights supersede mans laws in this regard. But then again, so many of them do not believe in God given rights. Yeesh, reality is going to suck.
 
from the article
According to a leading global watchdog, American democracy is now more imperiled than at any point since the 1960s, marked by a precipitous decline in press freedom – driven by mounting pressure from the Trump administration in the form of threats, criminal investigations, politicized regulation, frivolous lawsuits and, for public media, catastrophic funding cuts.
 
from the article
According to a leading global watchdog, American democracy is now more imperiled than at any point since the 1960s, marked by a precipitous decline in press freedom – driven by mounting pressure from the Trump administration in the form of threats, criminal investigations, politicized regulation, frivolous lawsuits and, for public media, catastrophic funding cuts.
Amazing twist on reality.....what has led up to this day, it wasn't Trump. I tend to think "the Build a burgers", World Economic forum, WHO, Illuminati, UN, Trilaterals...., and the list goes on. Heck, it started before Trump was born as far as that goes....NDAA 2013 was when the press was officially taken over and paid off by today's deep state.

They are all running scared..
 
Amazing twist on reality.....what has led up to this day, it wasn't Trump. I tend to think "the Build a burgers", World Economic forum, WHO, Illuminati, UN, Trilaterals...., and the list goes on. Heck, it started before Trump was born as far as that goes....NDAA 2013 was when the press was officially taken over and paid off by today's deep state.
Then there's the conspiracy theory that "They" deliberately sank the Titanic in order to kill people opposed to the creation of the Federal Reserve. As you suggest, this shit goes back a long time. My personal theory is that the authoritarian state in the U.S. really started with the automobile ... once people accepted that the government had the right to regulate everything about the automobile, the masses were more willing to accept the same intrusion into other aspects of their personal lives. It seems to me that quite a lot of this started in the late 1800s and early 1900s (which conveniently includes the communists coming into power in Russia, World War 1, and the Federal Reserve). Or not. For all I know the ancient Egyptians probably felt the exact same way.
 
Yeah, I read through this twice and didn't see President Trumps name anywhere???
It's mentioned on the actual page.
"Meanwhile, organizations that are supposed to be independent like the FBI and the FCC, our radio and television regulator, have also been targeting press freedom under Trump-aligned leadership, with the FBI raiding a reporter’s home and the FCC threatening ABC’s TV licenses after Jimmy Kimmel made a joke about Melania Trump."
 
It's mentioned on the actual page.
"Meanwhile, organizations that are supposed to be independent like the FBI and the FCC, our radio and television regulator, have also been targeting press freedom under Trump-aligned leadership, with the FBI raiding a reporter’s home and the FCC threatening ABC’s TV licenses after Jimmy Kimmel made a joke about Melania Trump."
Oh good grief.

Like LEFTIST outlets haven't had ducks every TIME they've been criticized by the conservative right -- on the media, in public, or in private--and done their LEVEL BEST to SHUT DOWN the other side's right of free speech.

While their own is FAR more egregious.

The bleeding head of Trump, par example, n'cest pas?

Shoe's a little uncomfortable on the other foot, huh?
 
Not that this has anything to do with "adversarial clothing," but a little to do with my comment about a lot of this U.S. authoritarian BS seemed to have started in the late 1800s and early 1900s. In the mix right now is whether Trump can put his face on a coin, so I'm researching when living people have appeared on U.S. coins. So far I've found seven coins, five of which were outright commemoratives that didn't circulate, one that may or may not have seen actual circulation (Calvin Coolidge appeared on a 1926 silver half-dollar coin while he was still in office), and one that definitely was in actual circulation (Franklin Roosevelt appeared on a 1936 One Peso coin for the U.S.-occupied Philippines also while he was still in office). And I came across the interesting trivia that the first President to appear on a U.S. coin was Lincoln ... on the 1909 penny (there's that early 1900s thing again, when things changed not necessarily for the better) which was very clearly intended to be only a commemorative for the 150th anniversary of Lincoln's birth and never meant to become a widely circulated coin. All of this being fairly deep into coin collecting trivia that normal people could give a rat's ass about but nonetheless supporting Trump's "right" to put himself on a U.S. coin.
 
And there are plenty of people poking and prodding. A fine example:


Flock Safety Hardcoded 53 Passwords in Police Cameras​


January 10, 2026


By ByteBot
Share




Security researcher Ben Jordan discovered this week that Flock Safety—whose 90,000 surveillance cameras track 20 billion vehicle scans monthly for 5,000+ U.S. police departments—hardcoded the same password 53 times across its infrastructure. CVE-2025-59407 (CVSS 9.8 Critical) documents the most egregious example: password “flockhibiki17” baked into Android apps running on license plate readers. The Wi-Fi access point password? Literally “security.” A button sequence on the device back grants full root access. These aren’t edge cases—they’re architectural failures at a company pulling $300M annual revenue.
Moreover, cameras running Android 8 haven’t received security updates since 2021. Flock’s response to the 55-day-old token-minting vulnerability? Still unpatched. This is critical infrastructure security theater.

Not One Mistake—Fifty-Three Instances of the Same Failure​

Jordan’s research uncovered a default ArcGIS API key embedded in 53 separate JavaScript bundles. This auto-generated Esri credential carried nearly 1 million API credits and 50 administrative privileges with zero restrictions—no referrer limits, no IP allowlists, no origin checks. Furthermore, development credentials ran in production environments, exposing FlockOS’s entire mapping infrastructure.
What was accessible through this key? Live patrol vehicle GPS tracking. Body-worn camera locations. 911 call transcripts. License plate detection data. Officer mobile app locations. Drone telemetry. Names, addresses, phone numbers. Fifty private ArcGIS data layers consolidating surveillance data from 12,000 deployments: 5,000 police departments, 6,000 community HOA systems, 1,000 private businesses.
This wasn’t a developer forgetting to remove a test credential. Consequently, fifty-three instances signals absence of code review, secret scanning tools, security audits, or basic secrets management. At this scale, it’s systemic negligence.

Physical Access Equals Full Control​

Flock cameras installed on public streets are physically accessible to anyone with a ladder. The company’s physical security model? A button sequence on the device back creates a Wi-Fi access point (SSID “flock-54E823”, password “security”). Connect to it, enable Android Debug Bridge, gain full root access. 9News quoted researchers: “30 seconds with a stick.”

Additionally, exposed USB ports accept malicious devices that execute scripts with full permissions. Sixty Condor PTZ cameras were accessible from the open internet with no authentication—live feeds, 30-day video archives, settings, logs, all exposed. Jordan described watching “everything from playgrounds to parking lots with people, Christmas shopping and unloading their stuff into cars” without entering a single credential.
When surveillance tools lack basic physical security, they become liabilities. Police operational security—patrol routes, officer locations, tactical deployments—becomes public information for anyone willing to press a few buttons.

Four Years of Unpatched Vulnerabilities​

Every Flock device runs Android 8, which reached end-of-life in 2021. Four years of accumulating CVEs sit unpatched on cameras deployed across 49 states. The company offers no upgrade path. Even if Flock patches today’s vulnerabilities, the underlying OS remains Swiss cheese.
Multi-factor authentication? Only 97% of customers use it, and it only became default for new users in November 2024. Flock police login credentials trade on dark web marketplaces. The combination of stolen credentials and years of OS vulnerabilities creates compounding security debt on critical infrastructure.
This is the IoT lifecycle problem writ large: vendors ship hardware, abandon software support, leave customers with insecure devices indefinitely. Without regulatory requirements for security updates matching deployment lifespans, abandonware becomes the standard for “critical infrastructure.”

Real Abuses Enabled by Security Failures​

These vulnerabilities enabled documented surveillance abuses. Between December 2024 and October 2025, over 50 federal, state, and local agencies ran hundreds of searches tracking First Amendment protesters. A Texas police officer searched Flock’s nationwide network for a woman who’d had a self-administered abortion—illegal in that state. Federal immigration enforcement agents accessed databases from 18 Washington state police agencies, often without the agencies’ knowledge. Three officers used the system to stalk ex-partners across jurisdictions.
San Jose police ran 3,965,519 searches through Flock’s license plate database in one year. The ACLU and Electronic Frontier Foundation filed a lawsuit in November 2025 challenging these warrantless searches. Representatives Raja Krishnamoorthi and Robert Garcia launched a congressional investigation into “invasive surveillance practices threatening the privacy, safety, and civil liberties of women, immigrants, and other vulnerable Americans.” The FTC sought to probe Flock’s cybersecurity protections.
Community pushback is mounting. Redmond, Lynnwood, and Olympia, Washington, turned off their cameras in late 2025. Mountlake Terrace cancelled its contract. When security failures enable stalking, protest tracking, and reproductive healthcare surveillance, the irony becomes inescapable: tools meant to enhance security become weapons targeting the innocent.

How Developers Prevent Hardcoded Credentials​

CWE-798 (Use of Hard-coded Credentials) is entirely preventable. What went wrong at Flock represents a checklist of what not to do: no secrets management (hardcoding credentials in 53 files), no secret scanning (GitGuardian or TruffleHog would catch exposed API keys), no code review process that flags credentials, development keys running in production, no regular security audits, and slow patch response (55 days for a critical bug).
Prevention strategies exist: HashiCorp Vault or AWS Secrets Manager for credential storage, pre-commit hooks blocking credential commits, environment variable injection instead of hardcoding, explicit CWE-798 checks in code review checklists, security training teaching the “why” behind secrets management, third-party penetration testing, and bug bounty programs incentivizing responsible disclosure.
Industry best practices that Flock violated include changing default passwords (they used “security”), mandatory MFA (only 97% adoption), never exposing cameras to the internet (60 were publicly accessible), regular firmware updates (Android 8 reached EOL in 2021), physical security protections (button sequences grant access), and API restrictions (no referrer or IP limits on their key).
Flock Safety is now a case study in security debt at scale. Your mistakes might not compromise 5,000 police departments, but the lesson applies at every scale: secrets management, code review, security audits, and rapid patching aren’t optional. They’re table stakes for building systems people trust.

....


Around Richmond, there are hundreds of these things at just over head height on poles.

You don't even need a stick to poke the buttons on the back...
A button sequence on the device back creates a Wi-Fi access point (SSID “flock-54E823”, password “security”). Connect to it, enable Android Debug Bridge, gain full root access. 9News quoted researchers: “30 seconds with a stick.”

Additionally, exposed USB ports accept malicious devices that execute scripts with full permissions.
 
I view Flock cameras as an infringement on a persons right to due process. Same reasons why a lot of places ban speed cameras.

I'm not saying there should be privacy in public either. It's public. The eyes can't be trespassed.

If they want surveillance, go put officers out on the road. Not only does it build a better rapport with the community, but it gives jobs, and doesn't violate due process all at the same time.

Since more cameras have been put up, I've noticed less patrol vehicles, and in some cases, some departments getting smaller.
 
For years now, I have been flipping the bird skyward in case any drone or satellite was watching. Now it looks like I have to do the same at street level fo the benefit of any flock cameras in the area.
 
There is no expectation of privacy in the public arena. Deal with it. Tech is only going to get better.
I hate that concept. Not sure it should be accepted either.... imagine if all those advertisements we saw as kids to buy glasses to see thru clothing were true. One could not go into public without someone eyeing your naked body thru their glasses? I know the TSA gets away with it every minute of every day...........just the same. Will the day come when not only the emperor wears no clothes. The public is considered to be about every square inch once you leave your home.
 
There is no expectation of privacy in the public arena. Deal with it. Tech is only going to get better.
AFAIK, there's also no legal expectation of privacy in your own back yard or if you leave your curtains open. If someone can see you without unreasonable efforts, you're basically f****d as far as your privacy goes.

There once was an Internet site known as JennyCam. She set up cameras all over her apartment and you could watch her 24 hours a day. Sometimes I think she had the right idea to inoculate herself against the modern world. She knew beyond a shadow of a doubt that she was being watched every second of every day.

I don't know if it's still the case, but not so long ago it was reported that Great Britain had the largest number of public cameras per capita in the entire world. Not the Soviet Union, not a communist or police state country, but Great Britain. The only saving grace was that a big chunk of the cameras promptly quit working and the British government apparently didn't have the manpower or skillset to keep them all fixed at the same time. Somewhere in my collection of pictures is a sign of a camera on a wall in (I think) Barcelona's Plaza de George Orwell -- sometimes you just can't make up stuff that is stranger than reality.
 
So, if I print those last 2 photos and tape it to the tailgate of my work truck, what will happen?
Depends, IF (and that is a big IF), the reader either directly (Scan as a barcode and send it to the server/app), or indirectly (scan as a picture/image and detect both the text and any barcode and send all of the data (image itself, any text, and any embedded (barcode) data as well) all back to the server/app, AND the server/app uses SQL as a database AND the software that they wrote does not check for "data" in either the text or embedded in a barcode, THEN that SQL server may be vulnerable to what they call SQL injection. With SQL injection, you can "send" what is supposed to be data that can be "looked up" in the database, and instead have it break that lookup function and instead treat it as a command to actually manage the database. The first quote in the sequence finishes the original data "input" and if they don't filter their data coming in to prevent it, everything behind the quote (it may need a single or a double quote character to work), becomes the command that the SQL server interprets and performs. You can delete tables or data, or change things. The barcode above gives it a schema test command that it really can't compute, the system burps and ends up with data read errors for your "session".

There are worse commands to send, some way worse, but you have to know a few details about the database to guarantee direct hits that you may want to do. Think of it sort of like playing either Battleship or Minesweeper...
 
Top