Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

81–90 of 268 posts

Re: Hackers Got Inside a Flock Camera

#81

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

I always assumed Flock's security posture was like most other companies. It's nice to see confirmation.

I think I should add a "X'); DROP TABLE Cameras;--" bumper sticker to my car now.

Couldn't resist: https://github.com/EvanAnderson/whimsy/blob/main/Drop_Table_...

Re: Hackers Got Inside a Flock Camera

#82
post #39

> According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454. Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plat…

That same NH law perhaps more importantly limits ALPR use to law enforcement officers.

That might be debatable

https://ij.org/the-ij-database-of-alpr-abuse/

Re: Hackers Got Inside a Flock Camera

#83
post #48

Earlier quoted context omitted.

I poked around in the boot partition. The kernel is ancient! Linux version 3.18.71-perf-gaf770dc

3.18.71-perf-gaf770dc is a Qualcomm Android vendor kernel from roughly late 2017. The 3.18 branch went fully EOL in 2019, so nothing after that was ever backported to it.

2017 was also the year Flock was funded and founded and went through the YConbinator cohort.

But you would have thought that by 2021 when Andreessen Horowitz funded them or at least by 2025 [1] when both further funded them, someone would have actually done some minor due diligence. Coincidentally too, 2025 was when the flock surveillance matrix went up all over the country almost immediately.

We constantly hear that the magic of tech funding lies in the people, not even the product/service. These types of things always seem to uncover that that is effectively just a lie to cover up the ulterior motives of setting up a tyrannical surveillance matrix all around you … to protect the children, of course.

[1] https://www.flocksafety.com/blog/flock-safety-secures-major-...

Re: Hackers Got Inside a Flock Camera

#85
post #48

Earlier quoted context omitted.

I poked around in the boot partition. The kernel is ancient! Linux version 3.18.71-perf-gaf770dc

3.18.71-perf-gaf770dc is a Qualcomm Android vendor kernel from roughly late 2017. The 3.18 branch went fully EOL in 2019, so nothing after that was ever backported to it.

Security through obsolescence!

Re: Hackers Got Inside a Flock Camera

#86
post #44

> "We liberated hardware" Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.

liberation is often used to refer to something that, while technically legal, the people that are subject to it did not agree to

Re: Hackers Got Inside a Flock Camera

#87
post #10

I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on. (The above should not be read as supporting Flock or discouraging furt…

"Axon is Flock but worse" will be the next big fight as police departments are pulling a fast one and saying "we got rid of Flock" by switching to Axon.

This happened in a St. Louis suburb recently.

Re: Hackers Got Inside a Flock Camera

#88

Earlier quoted context omitted.

Why? Does Flock really care about encryption? It checks off a box for their sales team, even if it's done poorly.

Because data should be secure. Full stop.

If it increases development or operating costs by $1 they won't do it unless there are consequences that could cost them more than that.

Re: Hackers Got Inside a Flock Camera

#89
post #68

Earlier quoted context omitted.

Correct. YC gotta wear their creations with pride.

They won’t have that sort of moment of self reflection until someone does something like use Flock infrastructure to stalk and assassinate the CEO of another YC company and then it will only be brief and fleeting before they double down on supporting this kind of egregious behaviour. Some people are just wired that way.

I say these people should not be in charge of choosing who gets insane amounts of money and networking opportunities

Re: Hackers Got Inside a Flock Camera

#90

Earlier quoted context omitted.

TDIL my homebuilt Plex media server is more strongly encrypted than a Flock Camera

so is my all-passwords.txt file on my desktop

My passwords are in an encrypted block in a text file that can be unencrypted inline in an Emacs session with a keystroke sequence that looks like a cat just chased a mouse across the keyboard, and that's before entering the decryption password. To access it, an attacker would first have to learn Emacs. Pretty sure that's a post-quantum level of security.
Post reply on HN