7 ms·
Hackers Got Inside a Flock Camera. Its Data Shows How the System Works
- driverdan 17d agoThis reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577 https://news.ycombinator.com/item?id=49726577 Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera https://ddosecrets.org/article/flock-alpr-camera
- john_strinlai 17d agodo the articles have significantly different information/coverage to warrant two submissions?
- incee 17d agoI can't read the Wired article because I'm only allowed three excerpts and 15 ads a day at Wired.com
- john_strinlai 17d agosame, but i'm not sure how that's related to my comment. workarounds or alternate articles without significant new information are typically posted within the same submission, not separate ones.
- driverdan 17d agoUse the Bypass Paywalls Clean extension https://gitflic.ru/project/magnolia1234/bypass-paywalls-firefox-clean https://gitflic.ru/project/magnolia1234/bypass-paywalls-fire...
- driverdan 17d agoNo, they're the same article. I had only read 404's when I submitted them and I assumed they'd both be submitted regardless.
- fullstop 17d agoI poked around in the boot partition. The kernel is ancient! Linux version 3.18.71-perf-gaf770dc
- datakan 17d agoThe oldest supported kernel is 5.10 and that loses support in December. That's wild they are using a 3.X kernel
- iririririr 17d agoYou'd be surprised how many things you use daily that people still backport the bare minimum to clig to 2.4.x forever
- anitil 17d agoYeah I've seen plenty of kernels that start with a 2 with no forward path possible due to "we don't know how to get our driver working anymore"
- mrheosuper 16d agoI really hope those don't have access to any networks.
- iririririr 16d agogood chance the linux running in your high end phone's modem runs 2.x kernel. i dont deal with that anymorrle, but last one I saw with 2.x was the pixel 6 pro.
- mrheosuper 16d agoJust check, my 2YO phone runs kernel 6.6, not latest but i think good enough for production. Edited: I misunderstood what you mean, you were talking about the modem subsystem, sorry.
- Barbing 17d agoThanks. Few saw that post: https://news.social-protocols.org/stats?id=49726577 https://news.social-protocols.org/stats?id=49726577
- deleted 17d ago[deleted]
- client4 17d agohttps://archive.vn/NiIzH https://archive.vn/NiIzH
- ck2 17d agoso when do we get it flipped to a nationwide bird migration tracking system? as someone pointed out: let's make that "flock" name accurate also make it identify bird song, I am sure there are microphones on there
- kotaKat 17d agoSomeone should sell branded black trashbags with a spraypainted penis on them. We'll call it Cock Safety and help our community with patented JimmyHat technology to keep you safe and covered.
- smalltorch 17d ago>At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!
- iamnothere 17d agoI think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on. (The above should not be read as supporting Flock or discouraging further investigation.) > The camera’s logs also show the camera struggling with storage. Its logs recorded more than 27,000 “no space left on device” errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots. At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs. Lol
- jordanb 17d ago"Axon is Flock but worse" will be the next big fight as police departments are pulling a fast one and saying "we got rid of Flock" by switching to Axon.
- ofcrpls 17d agoAxon is the default for the on-body camera system. The barrage of cop tv shows use them as part of their promotional relationships. Flock decided to not attack their market, in stead go for the adjacent space.
- kotaKat 17d agoBonus points: https://fccid.io/X4GS06009/Internal-Photos/Internal-Photos-8930936 https://fccid.io/X4GS06009/Internal-Photos/Internal-Photos-8... "Page 17" in the document shows a spicy little chip. https://www.quectel.com/product/kg100s-amazon-sidewalk-module/ https://www.quectel.com/product/kg100s-amazon-sidewalk-modul... Axon not only includes a cell modem... they're on Amazon Sidewalk, baby. https://coverage.sidewalk.amazon/ https://coverage.sidewalk.amazon/
- mr_machine 15d ago
- stackghost 17d agoBut will it run Doom?
- drfloyd51 17d agoSo… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.
- FrustratedMonky 17d agoIt is bad. But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?
- voakbasda 17d agoA network connected device that can be hacked is a small step away from being the first foothold into its server. The fact that on-device security is this atrocious suggests that their server is not any better quality, which means hacking it would probably not take much effort.
- FrustratedMonky 17d agoI don't disagree. But there is some old rule about, even the best security can fail if the device is physically accessible.
- overfeed 17d agoThere are levels to defending against physical attacks, and Flock half-assed theirs by leaving the encryption key right on the file system, according to the reporting. Those more serious about security — like Apple — store keys in an "enclave" chip so it can't be easily extracted by an attacker doing the bare minimum
- jquery 17d ago
- goolz 17d agoWhy did we not get the cool dystopia ala Gibson's Chiba City?
- apercu 17d agoLate stage capitalism?
- calgoo 17d agoBecause we got the gray box IBM version instead...
- scarecrowbob 17d agoI remember walking over a hill into a rave in the Utah desert that we'd set up and thinking that it actually was the cyberpunk dystopia that I had been hoping for. That kind of stuff is around but maybe not evenly distributed or legible to large demographics. Unfortunately, so is the rest of the vicious horrorshow, equally illegible and equally uneven in distribution.
- SauciestGNU 17d agoInteresting that you frame it as "hoping" for a dystopia. Like even in our wildest imaginations we can't envision a future where society works for regular folks.
- scarecrowbob 17d agoI'm sympathetic to the problem that folks like Mark Fisher have laid out, in which (to paraphrase) "it is easier to imagine the end of the world than the end of capitalism", and that indeed might be one way to understand my feeling. I take your point; it makes sense. "Regular folks" is doing a lot of work, though. It may very well be the case that most of the material world which props up the idea of "regular folks" never was capital-R Real and insofar as the idea is a pleasant dream it is not a sustainable one. Proximate to me, often "regular folks" entail white folks unproblematically living their lives around the norms of US hegemonic capital interests. When I hear Pat the Bunny sing "show me utopia, I will call it a jail" I understand the feeling. I was, afterall, raised by Christians who believed in David Byrne's picture of "Heaven" as a place where "nothing ever happens". Those are the folks who have happily elected a few people to replace the Flock cameras here with Axon. Their vision of an ordered society is a bit chilling to me, despite the fact that they understand their project as both liberal and progressive. As I understand it, deviations from those cultural norms are already "dystopic" to the "regular folks" I know- if we somehow lost our ability to transmute sand into computing power and dead plants into motive power and had to go back to living in the cliff side then we'd no longer really be human, despite the fact that their enchanted sand and holy oil is literally destroying the ecology of the entire planet. This situation is, of course, already a distopia for the bands of Ute and Jicarilla Apache and Dine and Hopi and others living near me. And when I look at the kinds of technological survellience built into the material structures it feels easy enough to note that we already live in a dystopia. I have heard some specific dakota folks refer this situation to as post-apocalyptic and I am inclined to agree. If we accept that we're already in a dystopia and, further, that much of the hegemonic culture's idea of a "utopia" has already been a holocaust for several other groups of people, then hoping for a "dystopia" in that sense might seem a bit more coherent.
- FlockisYC2 17d ago[dead]
- blueoranges 17d ago[dead]
- deaux 17d agoTitle is missing "(YC S17)" after "Flock".
- SecretDreams 17d agoCorrect. YC gotta wear their creations with pride.
- Teever 17d agoThey won’t have that sort of moment of self reflection until someone does something like use Flock infrastructure to stalk and assassinate the CEO of another YC company and then it will only be brief and fleeting before they double down on supporting this kind of egregious behaviour. Some people are just wired that way.
- chrystalkey 17d agoI say these people should not be in charge of choosing who gets insane amounts of money and networking opportunities
- thesuitonym 17d agoThey should not be in charge of anything, but being a sociopath gets you obscene amounts of money and puts you in charge of all sorts of things.
- vibrio 16d agoI wish this was just an anecdote rather than an axiom.
- lightedman 17d agoLet's just use Flock cameras to track all top-level YC people, publish everything we possibly can. Absolutely and utterly eliminate their privacy until they learn to respect ours.
- blueoranges 17d ago[dead]
- blacklimetea 17d ago[dead]
- hk1337 17d agoI feel like most of this was already known when someone here in Dallas figured out they had wifi connectivity you could connect and get access. I may not have the details exactly correct but I think someone got access then.
- ohyoutravel 17d agoFlock is a scourge on democracy. Flock is YC. But looks like they did YC nearly ten years ago. Who knows what their pitch deck looked like? If they pivoted since then to their current sinister incarnation? I don’t see any evidence that YC is still actively supporting them. Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable proposition than funding Flock for their current use case of allowing police to stalk their ex girlfriends or mistresses.
- shagie 17d agoDon't have the pitch deck directly, but do have some of the "what things looked like then" at https://www.ycdb.co/company/flock-safety https://www.ycdb.co/company/flock-safety The front page then had "All the footage is yours. Your neighborhood 100% owns the data. Flock Safety will not share, sell, or access your data." Unfortunately, flock has been excluded from wayback, so can't see other views of that page. {insert Darth Vader: I'm altering the deal. Pray I don't alter it any further.} (+45m edit) https://bestpitchdeck.com/flock-safety https://bestpitchdeck.com/flock-safety appears to be the pitch deck from 2020. > ... > In 2019, Flock signed their first police department deal with Jersey Village, Texas. > The slides you see here are from Langley's pitch at a venture conference one month before closing a $47M Series C round in November 2020. The following July, Andreessen Horowitz led a $150M Series D investment in Flock as a cornerstone of their American Dynamism practice. Additional slides are included from keynote and sales presentations used in 2023. > ...
- deleted 17d ago[deleted]
- MBCook 17d agoIt’s not like this stuff wasn’t known to be a problem 10 years ago. We were already in Trump’s first term, it’s not like it was part of the early post 9/11 “secure everything” push. It was WAY after that. 10 years ago is no excuse.
- ohyoutravel 17d ago
- zzzeek 17d agoIf I had to guess now it works it would be: 1. Take pictures 2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes Did I miss something
- nullable_bool 17d agoThe system they log into is called DAVID(Driver and Automobile Information Database) which logs activity. If an officer access that information for unlawful purposes, they can be prosecuted. You probably wont believe it, but the reason you hear about cops stalking their ex's is because they got caught doing so.
- SoftTalker 17d agoHow many didn't get caught? Or did but the issue was quietly "handled" within the department.
- zzzeek 17d agoemphasis on "can"
- AngryData 17d agoI don't care if a small amount of cops get in trouble if the other 99% of the time they get away with it.
- petcat 17d ago> According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454. Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1]. [1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes
- Grimeton 17d agoThe images were deleted the moment they were uploaded. But the record in the log files persisted. The camera doesn't have enough memory to store that many data.
- tEem21 17d agoThis does not seem to be the case. 404media's article includes extracted (redacted) images
- petcat 17d ago> The images were deleted the moment they were uploaded. ??? > VIII. Records of number plates read by each LPR shall not be recorded or transmitted anywhere and shall be purged from the system within 3 minutes of their capture [...] But you're saying that these non-hit image captures were uploaded somewhere?
- Grimeton 17d ago- Camera takes picture - Camera pre-checks the picture for quality and that there's something on there that they want - Camera uploads picture to flock servers - Camera deletes picture locally - Rinse and repeat I could actually see this being done by three jobs in parallel. If there are a lot of images found on the camera then that's probably because the upload wasn't able to keep up with the amount of data that was created or they have a buffer of a few days or there's a cronjob that deletes these files every now and then... Unless they actually use the camera also as the storage, which would be really stupid, but sometimes people to stupid things.
- writtenone 17d agoA friend in China built a Flock overlay network that sends live video and audio from ~100 cameras near me to an AWS server for processing and search.
- mring33621 17d agoThis is one of the most interesting comments on here. Hints at unauthorized, illegal mass surveillance riding on top of authorized (but also possibly illegal) mass surveillance
- deleted 17d ago[deleted]
- SlightlyLeftPad 17d agoTotally agree, we already know Flock is inept and lies about obvious truths. I want to know more about this.
- driverdan 17d agoCan you provide more details? Do you mean 100 public cameras anyone can access?
- totallymike 17d agoWhy would you have a friend that does that
- Toslink 17d agoHow do I make friends like this?
- totallymike 16d agoI’m not sure, but I bet you could find some helpful referrals here https://www.justice.gov/epstein https://www.justice.gov/epstein
- 16d ago
- ktm5j 17d ago> "We liberated hardware" Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.
- outside1234 17d agoAnd my privacy? The threat to democracy? Does Flock own that? Why is always the poors that need to own morality?
- intrasight 17d agoBut we own the cameras
- soupfordummies 17d agoThat's also the biggest plot-hole in the first Star Wars movie. Princess Leia is supposed to be this righteous noble of the moral resistance and yet she STEALS the Death Star plans!
- overtone1000 17d agohttps://news.ycombinator.com/item?id=49422404 https://news.ycombinator.com/item?id=49422404
- thangalin 17d agohttps://i.ibb.co/WWWYznHX/flock-future.png https://i.ibb.co/WWWYznHX/flock-future.png ;-) See also: https://dave.autonoma.ca/blog/2019/06/06/web-of-knowledge/ https://dave.autonoma.ca/blog/2019/06/06/web-of-knowledge/
- catidegla 17d ago[flagged]
- killbot5000 17d agoThis is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access. Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
- wat10000 17d agoThe question is, why should they care at all? Will this hurt their business?
- ryandrake 17d ago[dead]
- fn-mote 17d agoWould the DNC in the last US national election count?
- thereforegrin 15d agowas there really any meaningful fallout though?
- afavour 17d agoQuite potentially, yes. Their name is already mud among many voters, if they're shown to be treating data insecurely then that's another reason why local governments might consider terminating contracts with them.
- NichoPaolucci 17d ago
- wilburTheDog 17d agoI wonder if a stingray could be used to force a software update in a flock camera. If so maybe it could brick all the flock cameras it can connect to.
- crumpled 17d agoYeah, you could potentially MITM them with a rogue cell tower, I suppose. I'm curious about the researchers still having the device. They could also see all the cloud endpoints that were being accessed. Are they secure?
- overfeed 17d agoLinux 3.x has a lot of CVEs filed against its Bluetooth implementation.
- mrheosuper 16d agoDoes the image have bluetooth stack ? There is no reason to include bluetooth stack into the build.
- snarfy 17d agonice idea
- vayup 17d agoIf you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP. They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay. Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested. And also, infrastructure vulnerabilities like DNS config - no no, try harder. I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair. https://www.flocksafety.com/legal/vulnerability-disclosure-policy https://www.flocksafety.com/legal/vulnerability-disclosure-p...
- dokyun 17d agoAntisec was right.
- lenerdenator 17d agoIt'd be interesting to know how much of that they put second to "Americans seem to like using our hardware as targets for firearms, reciprocating saws, spray paint, and garbage bags" in their list of corporate concerns.
- ipdashc 17d agoThis looks like a pretty reasonable policy to me all things considered. And no, I'm no fan of Flock. But they do run security cameras for the cops, they can't just say go ahead, go wild on all our customers' cameras. The lawyers would throw a fit. The carveouts for stuff like configuration and DNS are entirely reasonable. Have you ever been behind a security@ email before? You get a lot of BS reports of that sort.
- vayup 17d agoIt's reasonable to not have a VDP for the reasons you mentioned. But not reasonable to have a useless one just so it appears they have a VDP.
- deleted 17d ago[deleted]
- inanutshellus 17d agoCurious how/why all this negative attention is focused directly on the Flock brand (current example notwithstanding)? Seems like if I were a competitor of Flock I'd be pretty happy right now and all this negative press is making them artificially cheap to buyout right now. Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this level of attention... not on the overarching issue of surveillance-state-ing, but of one particular company.
- IAmBroom 17d agoFlock has over 80% of the US market. You've seen this level of attention on a market leader before: on Microsoft, on Adobe, and others.
- 0xbadcafebee 17d ago1) Flock developed a nationwide network to track innocent people, tried to get in as many places as possible, and handed law enforcement agencies carte blanche access with virtually no oversight. Their whole schtick was being the mass surveillance company, and striking fear into people's hearts, in order to prevent crime. Despite being founded in 2017, they quickly reached hundreds of thousands of cameras installed. 2) The US Executive branch formed concentration camps and a private army, and started using this nationwide mass surveillance network to track down any brown people with a Spanish accent to lock them up in dangerous squalid conditions and/or deport them with no trial. This is an immediate, nation-wide harm being done to millions of Americans, and this new company is enabling it.
- thesuitonym 17d agoI can't speak for everybody, but in my case, my city has Flock cameras. It does not have Motorola, Rekor, Leonardo, or Axon.
- deleted 17d ago[deleted]
- anguishe 17d agoI wonder if they were able to find any of the Bluetooth signal-data these cameras are said to be obtaining from devices within its' vicinity. This in itself is wild, im glad they're coming down around where I am
- deleted 17d ago[deleted]
- crumpled 17d agoThe article says that Flock says "their cameras don't do facial recognition" The cameras don't, but they don't say the system doesn't. They don't say facial recognition isn't a click away through another integration. I would absolutely assume that any system that sends your image to LE is part of a facial recognition system in practice. We know now that the cameras do recognize people and intentionally transmits images of them, for later identification.
- sixothree 17d agoCommented something similar at the same time. I hate weasel wording like this. There is nothing that prevents this data from being used that way now or in the future. edit: And to be clear, the cameras specifically recognize and record people for a reason. This does not appear to be a fault in the system. One reason might be off-camera facial recognition.
- iAMkenough 17d agoI’m sure the first approach has been ingesting vehicle registration data into Flock servers so that your ID photo pops up when your license is captured. It seems the inevitable next step would be post-processed facial recognition (checked against those ready-for-the-taking ID photos) in their OS Investigator platform.
- realo 17d agoWith that kind of protection it is guaranteed that that no Flock camera will ever be sold in Europe after december 2027... CRA et al... I wonder what would happen if one of their customers asked for a 62443-4-2 certificate of compliance?
- crumpled 17d agoInteresting to note that if you don't look like a car or a person, through "adversarial fashion" or some other visual trick, your image potentially won't leave the camera and won't reach the flock cloud for further analysis.
- jklinger410 17d agoIt's surprising that an American company would forego so many common sense safety and security mechanisms just to protect their bottom line.
- 4b11b4 17d agoThe other day I was imagining that everyone can just own any device near them. I suppose this implies that we have the resources and access to a capable model
- Grimeton 17d agoAll these cameras do is pre-select the images that are worthy uploading. Everything else happens at Flock. That's why they don't give anything about the camera's security. The images are all from a public place, so no privacy expectations and what's theworst that could happen? Someone uploads their cat images or the pr0n collection? Ai figures that one out rather quickly.
- dpkirchner 17d agoAssuming the point of these cameras is security (and not just surveillance for stalker cops), being able to upload replacement footage would subvert that entirely. This has been a feature of many spy and cops/robber movies.
- Grimeton 17d agoThe point of these cameras is to deliver as many images of good quality as possible that show something of interest like a person, a car's numberplate and so on. I almost guarantee you, if the camera even has a SIM-Card then it's pre-configured with all the necessary information to find and join the mobile core network via APN. It turns on, joins the core network, gets handed an ip address and additional information like a servername/ip as its reporting endpoint, establishes the connection and starts taking pictures that it then sorts out and uploads. That's pretty much it. No login credentials, no complicated protocols, nothing. The things is identified via IMEI, Mac or some other burned in "serial" and that's all that's necessary to make it happen. So there are no credentials that could get lost, no technology that would be worth anything, access is being controlled on the network side and the images that are being taken are from a public place with no expectation for privacy. The core system only has to be secure enough so that it doesn't get hacked via an open bluetooth tty or something and everything else is handled by the network it belongs to. That's why DNS manipulation and similar stuff doesn't get you anywhere. Besides that, it has to be cheap and doesn't have to adhere to any security standards whatsoever. It's a pole with a mini camera and a solar cell that can just be vandalized by the next person that shows up.
- 16d ago
- Jeremy1026 17d ago[flagged]
- joquarky 17d agoTeenagers are more easily manipulated into creating anti-social technology.
- imthatsteve 17d agoTyranny of government invites terrorism from its constituents. We have all heard the argument that when corporations intentionally make the legal option worse it drives otherwise law abiding customers to pirate the content instead because piracy provides a better service than paying the corporation for their kneecapped product. I dont see how the same thing doesnt apply to governments. The people tell you over and over they dont want to live under a surveilance police state. So natually the corporations and government work together to create a fascist police state and they expect the people to be good little slaves and simply sell their souls to their government. Especially in the day of ai when they could just fake those images incredibly easily to frame someone. They dont need a patsy the next time they jfk someone they just find some sucker with a weak alibi from a list of potential suckers and then fake some cctv images and cell phone data and they can put you where ever they want to. The only real defence is to buy your own body cam and document every moment of your life so you can have competing evidence. At this point im surprised damaging the cameras is the only thing these activists are doing. I wouldnt be surprised to see flock employees and corrupt politicians finding bombs under their cars. Which will likely be used to justify more cameras which will only intensify the terrorist activity. The tree of liberty is long overdue for a good watering.
- worik 17d agoI disagree. If your solution is revolution you misunderstood the problem, and you'll make it worse We still have vestiges of democratic institutions we can use to constrain and controll the state. The blood letting, pain and suffering you are calling for is much worse than the private power's attack on privacy, and destroys the one effective tool (what remains of your Republic) that you have to fight them Instead of fighting to destroy your republic, struggle to protect and restore it
- SlightlyLeftPad 17d agoNext headline: Flock declares Hacker News a terrorist organization.
- vibrio 16d agoDoh! (Switches on vpn)
- LetsGetTechnicl 17d agoReally hoping some good guy hacker manages to take them all down somehow
- phkahler 17d ago>> Flock insists its cameras do not perform face recognition. Probably technically true. But since the cameras detect people that makes it easier for their backend system to do face recognition.
- NuclearPM 17d ago1984 but stupid-mode.
- deleted 17d ago[deleted]
- coldbrewed 17d agoMove fast and break things* * Privacy, civic trust, society if you get a chance! This is the end product of tech leadership taking fat rips of disruption cocaine for the last 15 years. Flock Safety got VC money so that they could build a panopticon. There is nothing surprising about the fact that they did a hack job with terrible security; the fact that their service names are various types of alcohol is beyond parody. Oh well, at least Flock Safety's IPO will be a critical cash infusion in the pursuit of building the torture nexus so that's cool.
- carefree-bob 17d agoThis is SOP for IOT devices. I am beginning to think we need to regulate this stuff, because it is ubiquitous. The device manufacturers do not have a culture of security.
- coldbrewed 17d agoThere are much better ways of device enrollment; at a minimum they could require device activation that doesn't blindly use a token with no further checks.
- carefree-bob 17d agoI'm concerned about publicly accessible devices containing secrets also. These are not physically secure places to store keys, they are mounted on street lights where anyone with a ladder can get the key material out of the device. It's like they have no threat model in place.
- autoexec 17d agoHaving hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have been enough vulnerabilities found in Flock's systems that it's pretty clear they aren't concerned about their security and it's plainly obvious that they don't care at all about our privacy or security. Even if we decided that this level of mass surveillance on the American public was acceptable to us, Flock Safety/Flock Group as already demonstrated that they can't and shouldn't be trusted to implement it.
- whatshisface 16d agoI too am appalled by the inefficiencies of the bureaucracy of the Gestapo. A serious threat to the state and the people could take days to reach the correct authorities. Only zhast month a smuggler escaped zhe guards, no doubt an agent of foreign intelligence.
- ErigmolCt 16d agoI get the joke, but this is kind of why the security issue matters
- socksy 16d agoBtw, Germans have no problem with pronouncing the letter L (before a vowel, anyway)
- whatshisface 15d agoEast Germans also wouldn't criticize the Statsi as a show of loyalty, and nobody would read about a security failure in the state news. So the story must be told by one of its characters. :-)
- fedpost 16d agoI for one welcome the incompetence. Godspeed to whoever is able to deploy a build to the whole device fleet that burns SoM boot protection fuses to an image that doesn't do anything hard bricking their entire network.
- aussieguy1234 17d ago> This camera is missing Android security updates for the last eight years. Right. So expect thousands of Flock cameras to be hacked soon. Possible perps include foreign intelligence agencies (Khamenei in Iran was tracked down for his assassination using Iranian traffic cams), stalkers, domestic violence perps tracking their victims, the list goes on.... More than likely though, multiple of the above.
- KennyBlanken 17d agoIt's always funny how such a "law and order" company not only lies through their teeth but also maliciously files false police reports. As in there's literally video evidence of them calling the police and telling the police things that are not happening. It's also really annoying me that police departments around the nation are petulantly implying they were "forced" to do this because of lawlessness and silly-villain karens...also claiming, without the press even remotely challenging them, that they're disappointed because "we believe they work." There literally isn't a single fucking shred of evidence that Flock cameras do jack shit, that isn't from a study Flock paid for, which heavily cherry-picked communities, particularly ones with very low crime rates where a Flock camera happened to be involved and the crime rate which was already low dropped by a couple crimes a year and resulted in a "200% reduction in crime."
- deleted 16d ago[deleted]
- ErigmolCt 16d agoAnd this seems designed around the assumption that the physical camera can be trusted indefinitely
- fractal618 16d agoWhat could go wrong?
- DarmokTanagra 16d ago[dead]
- br0ceph 16d agoif this data is public information, then why does it need encrypted secrecy, paywalls, or any kind of gatekeeping? if the information does need to be protected from the public, then it must be private data and flock is an illegal system