Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

101–110 of 268 posts

Re: Hackers Got Inside a Flock Camera

#101
post #94

Earlier quoted context omitted.

You can achieve 50MiB/s if that's all that you're doing. I've worked with some DSPs (TI's DaVinci line) where some operations would abort if DDR was overwhelmed. For example, passing a frame of video (YUV) into the peripheral which can resize the overall image, would fail if the system was busy with other DMA transfers. You could attempt to resize again, but there were no guarantee that it would complete successfully…

They can choose the SoC that would be able to fill the requirements. Eg. almost all Rockchip SoCs have NoC with configurable QoS on master ports (even the cheapest IP camera targetted SoCs that cost like 2-3$), or some other interconnect mechanism that can make it so that SDRAM controller gets tasks in some user selected priority order (eg. you deprioritize CPU in favor of camera interface and other things). This is…

That's why I was asking if it was an older model initially.

Re: Hackers Got Inside a Flock Camera

#103
post #90

Earlier quoted context omitted.

so is my all-passwords.txt file on my desktop

My passwords are in an encrypted block in a text file that can be unencrypted inline in an Emacs session with a keystroke sequence that looks like a cat just chased a mouse across the keyboard, and that's before entering the decryption password. To access it, an attacker would first have to learn Emacs. Pretty sure that's a post-quantum level of security.

Obligatory relevant xkcd: https://xkcd.com/538/

Re: Hackers Got Inside a Flock Camera

#104
post #44

> "We liberated hardware" Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.

I don't get the impression that anyone writing about this thinks it's legal. I think the argument would be that it's justified.

Then why bother using that language? The camera doesn't need rescuing, why not just "we took".

Also, is it really justified? Did we learn anything useful here that we didn't already know? There's more effective ways to push back against Flock, townships (like my own) are having plenty of success stories without stealing anything.

Re: Hackers Got Inside a Flock Camera

#105
If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP.

They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay.

Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.

And also, infrastructure vulnerabilities like DNS config - no no, try harder.

I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair.

https://www.flocksafety.com/legal/vulnerability-disclosure-p...

Re: Hackers Got Inside a Flock Camera

#106

This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. U…

The question is, why should they care at all? Will this hurt their business?

Re: Hackers Got Inside a Flock Camera

#108

This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. U…

The question is, why should they care at all? Will this hurt their business?

Is there any recent example of a company getting breached and its data exfiltrated, where the business was actually hurt? I predict we'll get a standard boilerplate "We take security very seriously" press release, a narrative that blames the evil hackers entirely and not the company's negligence, and then that will be that.

Re: Hackers Got Inside a Flock Camera

#109
Curious how/why all this negative attention is focused directly on the Flock brand (current example notwithstanding)?

Seems like if I were a competitor of Flock I'd be pretty happy right now and all this negative press is making them artificially cheap to buyout right now.

Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this level of attention... not on the overarching issue of surveillance-state-ing, but of one particular company.

Re: Hackers Got Inside a Flock Camera

#110

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

It is bad. But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?

i think this is actually good, because there are differences between the images they found, and security settings that the company claimed.

They had not admitted before to tracking people, but their software is clearly submitting them. They had not admitted before to looking at bumper stickers, but turns out they do.

I wonder if they could find all cars with Bernie Sanders bumper stickers within X blocks of a polling place.. I can imagine that (or similar queries) might be very useful in the wrong hands.

Post reply on HN