5 ms·
This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to imple
by killbot5000 17d ago
This is pure laziness aka “reduced time to market” on the part of Flock.
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
- wat10000 17d agoThe question is, why should they care at all? Will this hurt their business?
- ryandrake 17d ago[dead]
- fn-mote 17d agoWould the DNC in the last US national election count?
- thereforegrin 16d agowas there really any meaningful fallout though?
- afavour 17d agoQuite potentially, yes. Their name is already mud among many voters, if they're shown to be treating data insecurely then that's another reason why local governments might consider terminating contracts with them.
- NichoPaolucci 17d agoAny breach of security on a system like this is a big flashing red-alert to me. If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated. Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.
- sixothree 17d agoApparently police are accessing the network via their personal devices. I highly doubt their security practices online are any better than this. I wouldn't be surprised either to see things that chinese manufacturers do such as intentional back doors. Overall this goes from disappointing to fairly repugnant.
- iAMkenough 17d agoAllegedly you can buy credentials on the darkweb to perform national searches. Might explain why some of the logged reasons for recent searches were “LMAO”
- DANmode 17d agoThe normal explanation is plenty, unless you’ve never met, read about, or heard anyone talk about, law enforcement officers (who are human beings - for better and for worse).
- wat10000 17d agoHow many of us have had coworkers who put something like that into a commit message? And that's a message that's at least notionally supposed to be helpful to you or your coworkers, rather than existing purely for the purposes of oversight you don't want in the first place.
- iAMkenough 17d ago
- MattDaEskimo 17d agoFeels like their purpose is to test the boundaries, take the hits, and eventually sell off
- darksim905 17d agoThey want the good, bad and ugly to flock to them as it were and vaporize them so Axon and Motorola Solutions can just pick up right where they left off. And people will just ignore or forget it because it's not the same company.
- dietr1ch 17d agoI really hate how Product Managers somehow get to take the reins of engineering teams instead of having to sell them product ideas. It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.
- pixl97 17d agoBecause software engineering is not professional engineering. Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult.
- robocat 17d agoDo you feel like an inadiquate imposter or something? I'm assuming you work in software. Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design. Or read about engineering failures like flight QF32 (mostly a success story): A paperwork review showed that the required signatures were missing from 131 out of 138 retrospective concessions issued between 2009 and 2011 https://admiralcloudberg.medium.com/a-matter-of-millimeters-the-story-of-qantas-flight-32-bdaa62dc98e7 https://admiralcloudberg.medium.com/a-matter-of-millimeters-... Australian Quantas, with a UK Rolls Royce engine on an Airbus, with engines maintained in Aussie. Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems. Certification matters less than you might think across international borders. Perhaps I'm a cynic, but beliefs in certification seem so irrational to me. What is it? Jealous desires for status? Desire to have guilds/gatekeepers? Complete misunderstanding of how safety occurs in "real" engineering?
- stonogo 17d agoYour conclusion seems at odds with your evidence: the quote you reference indicates that a professional engineer was meant to examine the 'retrospective concessions' and did not. The result was that no qualified engineer was taking responsibility for their quality. Fixing the process meant getting credentialed engineers to assess and incur liability for the solutions, which is how the professional engineering licensure system is supposed to work.
- teraflop 17d agoThe flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false. If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.
- QuiEgo 17d agoDon’t worry, your elected representatives won’t be bothered by trivialities such as facts either way.
- toomuchtodo 17d agoThey can be recalled and/or replaced, as many have who voted for data centers. They fought against datacenters. Now they are running for local offices - https://www.theguardian.com/us-news/2026/sep/15/datacenters-local-elections https://www.theguardian.com/us-news/2026/sep/15/datacenters-... - September 15th, 2026 https://news.ycombinator.com/item?id=49375000 https://news.ycombinator.com/item?id=49375000 (citations)
- shimman 17d agoDon't know why you're getting downvoted, but hackernews is very anti-democratic in nature. One thing politicians quickly realize, especially local ones, is that you do have to be accountable to voters at the end of the day. One or two bad stories is enough to sink a local race too, or at minimum require a massive spend to overcome the negativity. Local politics is where you understand how effective a handful of people can truly be. Happy to read people are understanding the true power they have collectively instead of as individuals.
- toomuchtodo 17d ago
- Spooky23 17d agoIt’s not laziness, it’s hyper focus on compliance. CJIS is the policy maintained by the FBI that handles information security, which is derived from standards built around paper. Adding more weirdness, the details get worked out by each state. My guess is they encrypted whatever is criminal justice information (license plate hotlists, etc) or protected by local laws (DMV data) and left the rest to make it easier to deploy and service. Remember pictures of you or your car taken in public are not protected or in scope. Police tech is garbage and usually driven by federal grant spending. So it’s going to be interesting to see how Flock and Axon grow the business as it turns into a service model.
- krinchan 16d agoMy problem is that Claude kept screaming across several sessions that it echo'ed a default password for a local, ephemeral development container into a session across SEVERAL sessions. I get dinged continually for a vendor supplied container that writes an appropriately scoped access key to disk in plain text on startup (we are working to eliminate it but it requires migrating to an entirely new way of doing things the vendor only released earlier this year and I got derailed by other priorities). So like if established enterprises using off the shelf scanning software are breathing down my back about this...what the actual hell is happening inside flock that this was fine. Lol.