Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

121–130 of 275 posts

Re: Hackers Got Inside a Flock Camera

#121
post #80

Earlier quoted context omitted.

Yep. Clown show. > The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took. > I…

How could anyone possibly physically access a device that is just sitting out in public?

YC's finest https://www.ycombinator.com/companies/flock-safety

Re: Hackers Got Inside a Flock Camera

#122
With that kind of protection it is guaranteed that that no Flock camera will ever be sold in Europe after december 2027... CRA et al...

I wonder what would happen if one of their customers asked for a 62443-4-2 certificate of compliance?

Re: Hackers Got Inside a Flock Camera

#123

Earlier quoted context omitted.

The question is, why should they care at all? Will this hurt their business?

Any breach of security on a system like this is a big flashing red-alert to me. If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated. Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.

Apparently police are accessing the network via their personal devices. I highly doubt their security practices online are any better than this. I wouldn't be surprised either to see things that chinese manufacturers do such as intentional back doors.

Overall this goes from disappointing to fairly repugnant.

Re: Hackers Got Inside a Flock Camera

#124
Interesting to note that if you don't look like a car or a person, through "adversarial fashion" or some other visual trick, your image potentially won't leave the camera and won't reach the flock cloud for further analysis.

Re: Hackers Got Inside a Flock Camera

#125

This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. U…

The question is, why should they care at all? Will this hurt their business?

Feels like their purpose is to test the boundaries, take the hits, and eventually sell off

Re: Hackers Got Inside a Flock Camera

#126

The article says that Flock says "their cameras don't do facial recognition" The cameras don't, but they don't say the system doesn't. They don't say facial recognition isn't a click away through another integration. I would absolutely assume that any system that sends your image to LE is part of a facial recognition system in practice. We know now that the cameras do recognize people and intentionally transmits imag…

Commented something similar at the same time. I hate weasel wording like this. There is nothing that prevents this data from being used that way now or in the future.

edit: And to be clear, the cameras specifically recognize and record people for a reason. This does not appear to be a fault in the system. One reason might be off-camera facial recognition.

Re: Hackers Got Inside a Flock Camera

#128

This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577 Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera

I poked around in the boot partition. The kernel is ancient! Linux version 3.18.71-perf-gaf770dc

>gaf770dc

missing a d(gaf)

sorry, had to get that out!

Re: Hackers Got Inside a Flock Camera

#129

This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. U…

I really hate how Product Managers somehow get to take the reins of engineering teams instead of having to sell them product ideas.

It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.

Re: Hackers Got Inside a Flock Camera

#130

This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. U…

The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false.

If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.

Post reply on HN