Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

201–210 of 270 posts

Re: Hackers Got Inside a Flock Camera

#202

Earlier quoted context omitted.

The question is, why should they care at all? Will this hurt their business?

Any breach of security on a system like this is a big flashing red-alert to me. If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated. Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.

It's a red-alert to you and me, but Flock won't care. People already don't want these cameras in their cities, but police departments buy them anyway. What does it matter if there's one more reason you don't want them?

Re: Hackers Got Inside a Flock Camera

#203

Earlier quoted context omitted.

It is bad. But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?

A network connected device that can be hacked is a small step away from being the first foothold into its server. The fact that on-device security is this atrocious suggests that their server is not any better quality, which means hacking it would probably not take much effort.

A Silcon Valley startup with poor server-side security? Couldn't be!

Re: Hackers Got Inside a Flock Camera

#204

This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577 Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera

[deleted]

Re: Hackers Got Inside a Flock Camera

#205

Curious how/why all this negative attention is focused directly on the Flock brand (current example notwithstanding)? Seems like if I were a competitor of Flock I'd be pretty happy right now and all this negative press is making them artificially cheap to buyout right now. Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this leve…

I can't speak for everybody, but in my case, my city has Flock cameras. It does not have Motorola, Rekor, Leonardo, or Axon.

Re: Hackers Got Inside a Flock Camera

#206

Earlier quoted context omitted.

Interesting that they are a YC Company. Does yC do any ethics vetting of saying "No, let's stop fascism before it spreads?"

YC does no meaningful vetting at all. You can steal another YC entrant’s product and still get funded. https://deepdelver.substack.com/p/delve-fake-compliance-as-a...

many cases already public of rejected founders having their idea pushed on accepted founders with bad ideas.

Re: Hackers Got Inside a Flock Camera

#207
post #17

Earlier quoted context omitted.

I poked around in the boot partition. The kernel is ancient! Linux version 3.18.71-perf-gaf770dc

The oldest supported kernel is 5.10 and that loses support in December. That's wild they are using a 3.X kernel

You'd be surprised how many things you use daily that people still backport the bare minimum to clig to 2.4.x forever

Re: Hackers Got Inside a Flock Camera

#208
post #45

Flock is a scourge on democracy. Flock is YC. But looks like they did YC nearly ten years ago. Who knows what their pitch deck looked like? If they pivoted since then to their current sinister incarnation? I don’t see any evidence that YC is still actively supporting them. Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable propo…

It’s not like this stuff wasn’t known to be a problem 10 years ago. We were already in Trump’s first term, it’s not like it was part of the early post 9/11 “secure everything” push. It was WAY after that. 10 years ago is no excuse.

The NSA spying scandal happened under Obama even! IMO that was the defining moment for electronic privacy as a real political issue; before that we were very much in post-9/11 state of exception mode.

Re: Hackers Got Inside a Flock Camera

#210

This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. U…

It’s not laziness, it’s hyper focus on compliance. CJIS is the policy maintained by the FBI that handles information security, which is derived from standards built around paper.

Adding more weirdness, the details get worked out by each state.

My guess is they encrypted whatever is criminal justice information (license plate hotlists, etc) or protected by local laws (DMV data) and left the rest to make it easier to deploy and service. Remember pictures of you or your car taken in public are not protected or in scope.

Police tech is garbage and usually driven by federal grant spending. So it’s going to be interesting to see how Flock and Axon grow the business as it turns into a service model.

Post reply on HN