Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • > At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs.

    > When the camera did restart, another service left a final message in the logs: “A reboot was requested! ¡Adiós, Amigos!”

    Cool, so they were programmed by someone with the maturity of a teenager.

  • I wonder if a stingray could be used to force a software update in a flock camera. If so maybe it could brick all the flock cameras it can connect to.
  • Yeah, you could potentially MITM them with a rogue cell tower, I suppose. I'm curious about the researchers still having the device. They could also see all the cloud endpoints that were being accessed. Are they secure?
  • A friend in China built a Flock overlay network that sends live video and audio from ~100 cameras near me to an AWS server for processing and search.
  • This is one of the most interesting comments on here.

    Hints at unauthorized, illegal mass surveillance riding on top of authorized (but also possibly illegal) mass surveillance

  • Can you provide more details? Do you mean 100 public cameras anyone can access?
  • The article says that Flock says "their cameras don't do facial recognition" The cameras don't, but they don't say the system doesn't. They don't say facial recognition isn't a click away through another integration.

    I would absolutely assume that any system that sends your image to LE is part of a facial recognition system in practice. We know now that the cameras do recognize people and intentionally transmits images of them, for later identification.

  • Commented something similar at the same time. I hate weasel wording like this. There is nothing that prevents this data from being used that way now or in the future.

    edit: And to be clear, the cameras specifically recognize and record people for a reason. This does not appear to be a fault in the system. One reason might be off-camera facial recognition.

  • I’m sure the first approach has been ingesting vehicle registration data into Flock servers so that your ID photo pops up when your license is captured.

    It seems the inevitable next step would be post-processed facial recognition (checked against those ready-for-the-taking ID photos) in their OS Investigator platform.

  • Curious how/why all this negative attention is focused directly on the Flock brand (current example notwithstanding)?

    Seems like if I were a competitor of Flock I'd be pretty happy right now and all this negative press is making them artificially cheap to buyout right now.

    Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this level of attention... not on the overarching issue of surveillance-state-ing, but of one particular company.

  • Flock has over 80% of the US market.

    You've seen this level of attention on a market leader before: on Microsoft, on Adobe, and others.

  • All these cameras do is pre-select the images that are worthy uploading. Everything else happens at Flock.

    That's why they don't give anything about the camera's security.

    The images are all from a public place, so no privacy expectations and what's theworst that could happen? Someone uploads their cat images or the pr0n collection?

    Ai figures that one out rather quickly.

  • Assuming the point of these cameras is security (and not just surveillance for stalker cops), being able to upload replacement footage would subvert that entirely. This has been a feature of many spy and cops/robber movies.
  • > According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454.

    Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1].

    [1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes

  • That same NH law perhaps more importantly limits ALPR use to law enforcement officers.
  • The images were deleted the moment they were uploaded. But the record in the log files persisted. The camera doesn't have enough memory to store that many data.
  • This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577

    Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera

  • do the articles have significantly different information/coverage to warrant two submissions?
  • I poked around in the boot partition. The kernel is ancient!

    Linux version 3.18.71-perf-gaf770dc

  • So… all that data is literally there for any unauthorized person to walk up and take it.

    It’s not even suitably encrypted on device?

    Zero trust in anything Flock says.

  • > all that data is literally there for any unauthorized person to walk up and take it.

    All that data about ... license plates if you're willing to steal/damage private property. Seems like it would be a lot easier to setup your own ALPR.

    by xnx
  • It is bad.

    But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?

  • Yep. Clown show.

    > The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.

    > In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.

    Source: https://www.404media.co/hackers-stole-flocks-camera-software...

  • My working assumption based on what I hear out of Flock is that they have a public feature set (mass license plate surveillance for LEO) and a covert feature set (even more mass surveillance, beyond license plates and privacy agreements, for intelligence communities).
  • The devices are entirely open for all practical purposes - but worrying about individual cameras is silly, because they have no meaningful security at all around the API's to access all the cloud data - you can buy law enforcement credentials dirt cheap in dark web marketplaces to log in and track anyone/anywhere you want and access all footage.
  • has been for a long time - there's a sound engineer who developed quite a following (and is fairly involved with local movement hackerspaces) who demo'd how easy it was to hack Flock cameras nearly a year ago: https://www.youtube.com/watch?v=uB0gr7Fh6lY

    the Flock response has been 'it doesn't count if a Youtuber did it' lol: https://www.youtube.com/watch?v=0ADb-qQ5hMY

  • I always assumed Flock's security posture was like most other companies. It's nice to see confirmation.

    I think I should add a "X'); DROP TABLE Cameras;--" bumper sticker to my car now.

    Couldn't resist: https://github.com/EvanAnderson/whimsy/blob/main/Drop_Table_...

  • This is pure laziness aka “reduced time to market” on the part of Flock.

    It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.

    Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.

    Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.

    Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.

  • I really hate how Product Managers somehow get to take the reins of engineering teams instead of having to sell them product ideas.

    It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.