DOCUMENT Synter

Witness Camera Boot Sequence

How a single piece of consumer hardware tells DHS one story and the data commons another. The dual-firmware substrate beneath every Witness camera.

How we got here
SECRET//NOFORN//ORCON
DHS-FW-2037-WITNESS-014 DHS Cyber Forensics Division // Boot ROM analysis PAGE 1 OF 8 RE: Dual-firmware substrate, seized unit serial REDACTED
RECOVERED: Bahia Libre node, raid 2037-02-28 CUSTODY: DHS Evidence Locker / case 2037-BL-117

{dropcap} Yolanda mounts the camera at 14:32, a Tuesday. Workshop window, north light, partial view of the alley. From the outside it looks like she’s installing surveillance hardware in compliance with the SafeView Consumer Mandate. From the inside, she’s establishing a Witness node.

[!NOTE] Every Witness camera ships with two firmware stacks. They share sensor hardware. They never share data paths.

Boot into Sentinel Eye emulation

The camera identifies itself to the DHS registry as a SafeView Model SC-4000, serial number generated from a pool of decommissioned units. The registry accepts it. As far as DHS knows, Yolanda upgraded her existing SafeView hardware.

[!ASIDE] The pool of decommissioned serials is curated by the data commons — every number is real, every number was retired before the Exodus. None of them are flagged. None of them belong to anyone alive.

Establish compliance heartbeat

Every fifteen minutes, the camera sends a status packet to the SafeView cloud — a synthetic telemetry stream that Copernicus generates from a model trained on actual SafeView traffic patterns. Frame rate, exposure, motion events, connection quality. All fabricated. All statistically indistinguishable from a real SC-4000.

[!IMPORTANT] The heartbeat doesn’t just resemble SafeView traffic — it’s drawn from the same statistical distribution. DHS-side anomaly detection looks for cameras that report too cleanly. Copernicus injects the right amount of noise.

Initialize substrate layer

Beneath the Sentinel Eye emulation, the OHC firmware activates. Encrypted storage. Mesh relay pairing. Data commons handshake. The two firmware stacks share the same sensor hardware but maintain completely separate data paths.

The Sentinel Eye layer sees what DHS expects to see. The substrate layer sees what’s actually there.

Generate camera identity

Each Witness camera gets a cryptographic identity — a key pair anchored to the OHC trust chain. The private key never leaves the device. The public key registers with the data commons. This identity is the foundation of the provenance system: footage from this camera, signed with this key, can be verified by anyone with access to the commons.

Three lanes. Camera-side: the private key never leaves. Transit: hash + sign + commit to the OHC commons. Verification: public key + trust-chain anchor + verify operation. Anyone in the commons can verify any frame back to the camera.

[!QUOTE] A Witness camera is not a device. It is a position in a network of trust. The hardware is the easy part.

What this enables

When something happens in the alley — a sweep, a deployment, an arrest, a death — the substrate layer captures it, signs it, and hashes it into the commons. The Sentinel Eye layer keeps reporting nominal motion events to DHS. The two stories never touch.

The footage is verifiable. The provenance is unforgeable. The camera, on paper, is just another SafeView consumer install.

That’s the whole substrate. Everything else is built on top of it.

Exemptions cited

(b)(7)(E)
Investigative techniques and procedures.
(b)(1)
Classified national-security information.
SECRET//NOFORN//ORCON