3 ms·
Yep. Clown show. > The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially
by glaslong 19d ago
Yep. Clown show.
> The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.
> In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.
Source: https://www.404media.co/hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people-2/ https://www.404media.co/hackers-stole-flocks-camera-software...
- scottLobster 19d agoTDIL my homebuilt Plex media server is more strongly encrypted than a Flock Camera
- bdangubic 19d agoso is my all-passwords.txt file on my desktop
- antonvs 19d agoMy passwords are in an encrypted block in a text file that can be unencrypted inline in an Emacs session with a keystroke sequence that looks like a cat just chased a mouse across the keyboard, and that's before entering the decryption password. To access it, an attacker would first have to learn Emacs. Pretty sure that's a post-quantum level of security.
- dpoloncsak 19d agoObligatory relevant xkcd: https://xkcd.com/538/ https://xkcd.com/538/
- IAmBroom 19d agoIt's a forever-fresh reminder about security versus your own government, but for malicious hackers and bots: the physical trip to visit you costs more than half their infrastructure. Encryption matters, even if I would divulge everything long before the wrench appeared.
- syed_qutub3 19d ago[dead]
- mmooss 19d agoThey could use an LLM to lookup your HN posts and then to wrangle Emacs. Or just decrypt the text in another application - I doubt Emacs is the only platform for whatever crypto method you use. M-x rot13 ?
- antonvs 19d agoOh, did I forget to mention the encryption is implemented in Emacs Lisp? At some point, the attackers are just going to have to give up and start hitting me with a wrench. Joke's on them though - I'm an Emacs user, I like pain.
- mmooss 18d agoIt's interesting and fun to implement this stuff; I totally agree. Emacs is amazing. I worry people will get the wrong idea about security: The application used for decryption doesn't need to be the same as the one used for encryption, at least not for any serious attacker. That would be 'security through obscurity'. They need the encrypted text; they don't need Emacs. More importantly, no matter who you are, that you implemented the encryption yourself (?) is a major flaw - unless you have a cryptography team that has matured the implementation over a decade or so. Nobody is good enough to do that by themself. As the saying goes, anyone can create an encryption routine that they can't break.
- Quinner 19d agoHow could anyone possibly physically access a device that is just sitting out in public?
- Obscurity4340 19d agoIts impossible, I tell ya
- coldpie 19d agoYC's finest https://www.ycombinator.com/companies/flock-safety https://www.ycombinator.com/companies/flock-safety
- reaperducer 19d agoRuns Android. Has (wireless?) internet access. It seems that some enterprising Jolly Roger could start running a public mesh net on top of them without Flock even noticing.