

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- A friend in China built a Flock overlay network that sends live video and audio from ~100 cameras near me to an AWS server for processing and search.by writtenone
- The article says that Flock says "their cameras don't do facial recognition" The cameras don't, but they don't say the system doesn't. They don't say facial recognition isn't a click away through another integration.
I would absolutely assume that any system that sends your image to LE is part of a facial recognition system in practice. We know now that the cameras do recognize people and intentionally transmits images of them, for later identification.
by crumpled - > According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454.
Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1].
[1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes
by petcat - So… all that data is literally there for any unauthorized person to walk up and take it.
It’s not even suitably encrypted on device?
Zero trust in anything Flock says.
by drfloyd51 - This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577
Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera
by driverdan - This is pure laziness aka “reduced time to market” on the part of Flock.
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
by killbot5000 - Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have been enough vulnerabilities found in Flock's systems that it's pretty clear they aren't concerned about their security and it's plainly obvious that they don't care at all about our privacy or security.
Even if we decided that this level of mass surveillance on the American public was acceptable to us, Flock Safety/Flock Group as already demonstrated that they can't and shouldn't be trusted to implement it.
by autoexec - If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP.
They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay.
Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.
And also, infrastructure vulnerabilities like DNS config - no no, try harder.
I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair.
https://www.flocksafety.com/legal/vulnerability-disclosure-p...
by vayup