Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

231–240 of 268 posts

Re: Hackers Got Inside a Flock Camera

#232

Earlier quoted context omitted.

2017 was also the year Flock was funded and founded and went through the YConbinator cohort. But you would have thought that by 2021 when Andreessen Horowitz funded them or at least by 2025 [1] when both further funded them, someone would have actually done some minor due diligence. Coincidentally too, 2025 was when the flock surveillance matrix went up all over the country almost immediately. We constantly hear that…

In an ideal world they'd have people whose job it is to monitor upstream activity in the components used in the firmware and maintain this. Sounds like they did not have that.

[deleted]

Re: Hackers Got Inside a Flock Camera

#234

Curious how/why all this negative attention is focused directly on the Flock brand (current example notwithstanding)? Seems like if I were a competitor of Flock I'd be pretty happy right now and all this negative press is making them artificially cheap to buyout right now. Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this leve…

[deleted]

Re: Hackers Got Inside a Flock Camera

#235
post #225

Earlier quoted context omitted.

They can be recalled and/or replaced, as many have who voted for data centers. They fought against datacenters. Now they are running for local offices - https://www.theguardian.com/us-news/2026/sep/15/datacenters-... - September 15th, 2026 https://news.ycombinator.com/item?id=49375000 (citations)

Only a handful of states have any concept of a recall election.

Exactly. It helps they also control who can even run for office in any meaningful way. Nobody fights the left harder than Democrats. Good luck finding a representative that is against data centers, flock, Israel, congressional stock bans and pausing and regulating AI, views overwhelming popular with the majority of the actual American public.

Re: Hackers Got Inside a Flock Camera

#236

Earlier quoted context omitted.

2017 was also the year Flock was funded and founded and went through the YConbinator cohort. But you would have thought that by 2021 when Andreessen Horowitz funded them or at least by 2025 [1] when both further funded them, someone would have actually done some minor due diligence. Coincidentally too, 2025 was when the flock surveillance matrix went up all over the country almost immediately. We constantly hear that…

It's almost as if they paid a contractor to design the hardware back in 2017 and put all the funding into marketing(bribes) since then. Shocker.

"It's only a problem if your definition of done makes it one".

Re: Hackers Got Inside a Flock Camera

#237
post #152

Earlier quoted context omitted.

Because software engineering is not professional engineering. Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult.

Do you feel like an inadiquate imposter or something? I'm assuming you work in software. Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design. Or read about engineering failures like flight QF32 (mostly a success story): A paperwork review showed that the required signatures were missing from 131 out of 138 retro…

Your conclusion seems at odds with your evidence: the quote you reference indicates that a professional engineer was meant to examine the 'retrospective concessions' and did not. The result was that no qualified engineer was taking responsibility for their quality. Fixing the process meant getting credentialed engineers to assess and incur liability for the solutions, which is how the professional engineering licensure system is supposed to work.

Re: Hackers Got Inside a Flock Camera

#238
post #235
post #225

Earlier quoted context omitted.

Only a handful of states have any concept of a recall election.

Exactly. It helps they also control who can even run for office in any meaningful way. Nobody fights the left harder than Democrats. Good luck finding a representative that is against data centers, flock, Israel, congressional stock bans and pausing and regulating AI, views overwhelming popular with the majority of the actual American public.

My experience is that nobody fights the democrats harder than "leftists".

Re: Hackers Got Inside a Flock Camera

#239
post #105

If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP. They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY ca…

This looks like a pretty reasonable policy to me all things considered. And no, I'm no fan of Flock. But they do run security cameras for the cops, they can't just say go ahead, go wild on all our customers' cameras. The lawyers would throw a fit. The carveouts for stuff like configuration and DNS are entirely reasonable. Have you ever been behind a security@ email before? You get a lot of BS reports of that sort.

It's reasonable to not have a VDP for the reasons you mentioned. But not reasonable to have a useless one just so it appears they have a VDP.

Re: Hackers Got Inside a Flock Camera

#240

Earlier quoted context omitted.

The normal explanation is plenty, unless you’ve never met, read about, or heard anyone talk about, law enforcement officers (who are human beings - for better and for worse).

How many of us have had coworkers who put something like that into a commit message? And that's a message that's at least notionally supposed to be helpful to you or your coworkers, rather than existing purely for the purposes of oversight you don't want in the first place.

I would expect law enforcement coworkers to understand the law, department procedure, and public requests for their data. That’s expecting too much from the academy, I guess.

Those that fail to meet standards should be fired to spare the taxpayers from the lawsuits coming from AI-assisted complainants.

It’s also too much for Flock’s YC-funded technology to implement a field filter that rejects “LMAO” as a valid request.

At the very least, your local staff’s nationwide stalking credentials being harvested by phishing and abused by others should carry criminal negligence penalties. Governments should pass that liability onto this YC-funded startup company.

Post reply on HN