
From Camera to Courtroom – Four Points Where Trust in Video Footage Can Break
In September, the mayor of Boston stated that the city had permanently broken with Flock’s licence plate recognition system. The reason was not a hacker attack but a setting. In a 2025 pilot programme, around 45 cameras recorded passing vehicles, and the contract explicitly prohibited other agencies from accessing the data. The police even checked that sharing was switched off. Yet as early as the third day of the pilot, it turned out that other police forces were searching Boston’s data, because the manufacturer had switched on nationwide lookup “in error”. The feature was disabled, but the public only learned about the case this September, from the city’s annual surveillance report.
On 22 September, an article of a completely different kind appeared. Writing in SecurityInfoWatch, an Axis executive argued that in the age of generative AI, courts and investigators increasingly expect the authenticity of footage to be provable from the camera itself.
At first glance the two stories are unrelated. In fact, they are about two links of the same chain: the journey of a recording, which begins in the camera and, ideally, ends on an investigator’s desk or in a courtroom. Along this journey, trust can break at four points.
1. Creation: in the camera
A recording’s authenticity is decided where the image is born. With signed video, the camera cryptographically signs the video stream at the moment of recording, using a key unique to that device. If even a single frame is altered afterwards, the signature becomes invalid. At the end of August, ONVIF published the release candidate of its Media Signing Add-on, which provides a vendor-independent method for this. The final version is expected by the end of 2026.
This has two preconditions. The first is that the signing key is protected in hardware. On the Flock camera described in my previous article, the encryption key sat readable on the device’s storage. The second is that the device’s clock is synchronised, because a genuine recording with a wrong timestamp is of little use.
2. Storage: where and for how long
Every day of storage is a risk. Footage should be kept only as long as its purpose justifies, and you need to know where it physically is. With a cloud system, this is also a contractual question. Under the GDPR, the operator is the data controller and the provider is the data processor, and it is primarily the controller who is accountable for who can access the footage.
3. Access: who has seen it
Boston’s case is exactly about this. The contract was in order, and so was the setting – until the manufacturer changed it. The mayor’s reasoning was therefore to the point: the city will not use a platform where access rules, once set, can later be changed.
Another figure from the report is just as telling. According to the internal audit, officers ran 11,004 searches in the system, and around half of them had no case number attached. So the log existed, and in hindsight it showed exactly what had happened. Its real value, however, would have come from someone reading it along the way.
Three things follow for the design:
- personal accounts, assigned by role;
- sharing switched off by default, and checked regularly – not only at handover;
- a log that even the system administrator cannot delete without a trace.
4. Release: when the footage leaves the system
Export can be the weakest point of the chain: from here on, the recording is a file that can be copied, cut and forwarded. Released footage should therefore come with verification data (a signature or a hash) and a record of who handed it over, when and to whom. If the camera signed the footage, the recipient can confirm with a suitable verification tool that the recording is genuine.
The strength of the chain
The evidential value of a recording depends not on its strongest link, but on its weakest. In Boston, the chain broke at access. In the age of manipulated video, it is increasingly the creation that will be called into question. Today, security system design also means thinking through all four points of a recording’s journey in advance.
Sources: Boston Globe · GovTech · SecurityInfoWatch · ONVIF
