5 ms·
So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Fl
by drfloyd51 18d ago
So… all that data is literally there for any unauthorized person to walk up and take it.
It’s not even suitably encrypted on device?
Zero trust in anything Flock says.
- FrustratedMonky 18d agoIt is bad. But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?
- voakbasda 18d agoA network connected device that can be hacked is a small step away from being the first foothold into its server. The fact that on-device security is this atrocious suggests that their server is not any better quality, which means hacking it would probably not take much effort.
- FrustratedMonky 18d agoI don't disagree. But there is some old rule about, even the best security can fail if the device is physically accessible.
- overfeed 18d agoThere are levels to defending against physical attacks, and Flock half-assed theirs by leaving the encryption key right on the file system, according to the reporting. Those more serious about security — like Apple — store keys in an "enclave" chip so it can't be easily extracted by an attacker doing the bare minimum
- jquery 18d agoApple did that… eventually. Early iPhones weren’t very secure. Apple only got serious after they dominated the market and reducing the theft value of iPhones became a priority.
- overfeed 18d agoEven the cheapest commodity encryption chips have had this capability for well over a decade now, Unlike Apple, Flock are not a hardware pioneer, not by a long shot. The Android documentation has an example of how to use hardware keys, and a Chinese OEM (IIRC) was found using the example key provided by Android sample code - and yet that was more effort than Flock applied, since their ARM SoC support it.
- thesuitonym 18d agoA Silcon Valley startup with poor server-side security? Couldn't be!
- briffle 18d agoi think this is actually good, because there are differences between the images they found, and security settings that the company claimed. They had not admitted before to tracking people, but their software is clearly submitting them. They had not admitted before to looking at bumper stickers, but turns out they do. I wonder if they could find all cars with Bernie Sanders bumper stickers within X blocks of a polling place.. I can imagine that (or similar queries) might be very useful in the wrong hands.
- fullstop 18d agoIs this an older model? I could see them turning off or using weak encryption on media if the hardware couldn't keep up with the amount of data they were writing.
- ohyoutravel 18d agoThat would be an extremely bad trade.
- fullstop 18d agoWhy? Does Flock really care about encryption? It checks off a box for their sales team, even if it's done poorly.
- samudrijan 18d agoBecause data should be secure. Full stop.
- criddell 18d agoIf it increases development or operating costs by $1 they won't do it unless there are consequences that could cost them more than that.
- fullstop 18d agoIn a perfect world, yes, but this is a for-profit company and there's almost zero repercussion for doing it half-assed. They'd have to pay someone to implement it, and deal with the overhead and complexity. Now they are in a position where they can sell new models with enhanced encryption and more features.
- megous 18d agoI'm in the process of optimizing a bootolader for my various SoC/SBCs and even the cheapest, oldest least powerful SoC from 15 years ago can manage AES-CBC via crypto accelerator at 50 MiB/s. There's no excuse.
- glaslong 18d agoYep. Clown show. > The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took. > In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud. Source: https://www.404media.co/hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people-2/ https://www.404media.co/hackers-stole-flocks-camera-software...
- scottLobster 18d agoTDIL my homebuilt Plex media server is more strongly encrypted than a Flock Camera
- bdangubic 18d agoso is my all-passwords.txt file on my desktop
- antonvs 18d agoMy passwords are in an encrypted block in a text file that can be unencrypted inline in an Emacs session with a keystroke sequence that looks like a cat just chased a mouse across the keyboard, and that's before entering the decryption password. To access it, an attacker would first have to learn Emacs. Pretty sure that's a post-quantum level of security.
- dpoloncsak 18d ago
- deleted 18d ago[deleted]
- paimapi 18d agohas been for a long time - there's a sound engineer who developed quite a following (and is fairly involved with local movement hackerspaces) who demo'd how easy it was to hack Flock cameras nearly a year ago: https://www.youtube.com/watch?v=uB0gr7Fh6lY https://www.youtube.com/watch?v=uB0gr7Fh6lY the Flock response has been 'it doesn't count if a Youtuber did it' lol: https://www.youtube.com/watch?v=0ADb-qQ5hMY https://www.youtube.com/watch?v=0ADb-qQ5hMY
- xnx 18d ago> all that data is literally there for any unauthorized person to walk up and take it. All that data about ... license plates if you're willing to steal/damage private property. Seems like it would be a lot easier to setup your own ALPR.
- antonvs 18d agoYou don't think that because it's called a "license plate reader," that it only captures license plates, do you? Flock cameras capture the make, model, color, and body style of vehicles. They capture bumper stickers and other decals, as well as potentially identifying dents and scratches. They capture accessories like roof racks, bike racks, trailers, and toolboxes. The OP story covers some of this. There's more at: https://www.aclu.org/campaigns-initiatives/get-the-flock-out https://www.aclu.org/campaigns-initiatives/get-the-flock-out https://www.nytimes.com/2026/08/10/us/flock-cameras-can-track-every-car-in-america-police-love-them-citizens-dont.html https://www.nytimes.com/2026/08/10/us/flock-cameras-can-trac...
- DANmode 18d agoLicense plate data is bad enough (and unconstitutional in many jurisdictions, despite ubiquity). Also, there’s way more data on there than plate data.
- EvanAnderson 18d agoI always assumed Flock's security posture was like most other companies. It's nice to see confirmation. I think I should add a "X'); DROP TABLE Cameras;--" bumper sticker to my car now.
- runjake 18d agoMy working assumption based on what I hear out of Flock is that they have a public feature set (mass license plate surveillance for LEO) and a covert feature set (even more mass surveillance, beyond license plates and privacy agreements, for intelligence communities).
- leonidasrup 18d agoThe man who would choose security over freedom deserves neither. - Thomas Jefferson
- sumeno 18d agoDidn’t realize Jefferson misquoted Franklin
- imthatsteve 18d ago"The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants"
- stefangordon 18d agoThe devices are entirely open for all practical purposes - but worrying about individual cameras is silly, because they have no meaningful security at all around the API's to access all the cloud data - you can buy law enforcement credentials dirt cheap in dark web marketplaces to log in and track anyone/anywhere you want and access all footage.