Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

141–150 of 271 posts

Re: Hackers Got Inside a Flock Camera

#141

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

I always assumed Flock's security posture was like most other companies. It's nice to see confirmation. I think I should add a "X'); DROP TABLE Cameras;--" bumper sticker to my car now. Couldn't resist: https://github.com/EvanAnderson/whimsy/blob/main/Drop_Table_...

Bobby? Bobby Tables? Is that really you?

https://xkcd.com/327/

Re: Hackers Got Inside a Flock Camera

#142
All these cameras do is pre-select the images that are worthy uploading. Everything else happens at Flock.

That's why they don't give anything about the camera's security.

The images are all from a public place, so no privacy expectations and what's theworst that could happen? Someone uploads their cat images or the pr0n collection?

Ai figures that one out rather quickly.

Re: Hackers Got Inside a Flock Camera

#143

The article says that Flock says "their cameras don't do facial recognition" The cameras don't, but they don't say the system doesn't. They don't say facial recognition isn't a click away through another integration. I would absolutely assume that any system that sends your image to LE is part of a facial recognition system in practice. We know now that the cameras do recognize people and intentionally transmits imag…

I’m sure the first approach has been ingesting vehicle registration data into Flock servers so that your ID photo pops up when your license is captured.

It seems the inevitable next step would be post-processed facial recognition (checked against those ready-for-the-taking ID photos) in their OS Investigator platform.

Re: Hackers Got Inside a Flock Camera

#144

Earlier quoted context omitted.

Apparently police are accessing the network via their personal devices. I highly doubt their security practices online are any better than this. I wouldn't be surprised either to see things that chinese manufacturers do such as intentional back doors. Overall this goes from disappointing to fairly repugnant.

Allegedly you can buy credentials on the darkweb to perform national searches. Might explain why some of the logged reasons for recent searches were “LMAO”

The normal explanation is plenty, unless you’ve never met, read about, or heard anyone talk about, law enforcement officers (who are human beings - for better and for worse).

Re: Hackers Got Inside a Flock Camera

#145
post #105

If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP. They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY ca…

Antisec was right.

Re: Hackers Got Inside a Flock Camera

#146
post #73

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

> all that data is literally there for any unauthorized person to walk up and take it. All that data about ... license plates if you're willing to steal/damage private property. Seems like it would be a lot easier to setup your own ALPR.

License plate data is bad enough (and unconstitutional in many jurisdictions, despite ubiquity).

Also, there’s way more data on there than plate data.

Re: Hackers Got Inside a Flock Camera

#147
post #39

> According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454. Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plat…

The images were deleted the moment they were uploaded. But the record in the log files persisted. The camera doesn't have enough memory to store that many data.

Re: Hackers Got Inside a Flock Camera

#148

All these cameras do is pre-select the images that are worthy uploading. Everything else happens at Flock. That's why they don't give anything about the camera's security. The images are all from a public place, so no privacy expectations and what's theworst that could happen? Someone uploads their cat images or the pr0n collection? Ai figures that one out rather quickly.

Assuming the point of these cameras is security (and not just surveillance for stalker cops), being able to upload replacement footage would subvert that entirely. This has been a feature of many spy and cops/robber movies.

Re: Hackers Got Inside a Flock Camera

#149

This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577 Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera

do the articles have significantly different information/coverage to warrant two submissions?

No, they're the same article. I had only read 404's when I submitted them and I assumed they'd both be submitted regardless.
Post reply on HN