Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

241–250 of 270 posts

Re: Hackers Got Inside a Flock Camera

#241
post #193
post #105

If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP. They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY ca…

The TLS/SSL and DNS carveouts are pretty normal. There are a million security options for those services and enabling them all would often mean denying access to anyone running a browser/client more than a few weeks old. Documenting them all would be a PITA so most policies simply prohibit them entirely. Testing against customers is also a common prohibition for obvious reasons.

Hm... not normal in my experience. Not enabling a config is not a vulnerability in itself. If not enabling something means a security guarantee is broken (Eg: videos are accessible) then it is a vulnerability, and typically included in VDP, atleast VDPs that are in good faith.

Re: Hackers Got Inside a Flock Camera

#242

Earlier quoted context omitted.

Any breach of security on a system like this is a big flashing red-alert to me. If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated. Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.

Getting persistent access to Flock's internal network is a high-priority item for every US adversary, who doesn't want free intel collection on the movements of persons of interest? Knowing who the FBI and local cops are monitoring in is the counter-counter-intelligence cherry on top of a self-inflicted dragnet surveillance cake. Any entity with access to flock servers can virtually stake-out anyone/everyone driving…

I mean... currently any cop can do that, and it's a lot easier to bribe a single cop than to break into flock network.

https://edition.cnn.com/2026/08/26/us/flock-kentucky-police-...

A single cop can do it 2000 times it seems before they get caught

And it's not a lone case: https://www.washingtonpost.com/technology/2026/08/02/how-pol...

Re: Hackers Got Inside a Flock Camera

#243

Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have bee…

I too am appalled by the inefficiencies of the bureaucracy of the Gestapo. A serious threat to the state and the people could take days to reach the correct authorities. Only zhast month a smuggler escaped zhe guards, no doubt an agent of foreign intelligence.

Re: Hackers Got Inside a Flock Camera

#244

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

I always assumed Flock's security posture was like most other companies. It's nice to see confirmation. I think I should add a "X'); DROP TABLE Cameras;--" bumper sticker to my car now. Couldn't resist: https://github.com/EvanAnderson/whimsy/blob/main/Drop_Table_...

Makes you wonder if that could actually work

Re: Hackers Got Inside a Flock Camera

#245
post #17

Earlier quoted context omitted.

The oldest supported kernel is 5.10 and that loses support in December. That's wild they are using a 3.X kernel

You'd be surprised how many things you use daily that people still backport the bare minimum to clig to 2.4.x forever

I really hope those don't have access to any networks.

Re: Hackers Got Inside a Flock Camera

#246

I wonder if a stingray could be used to force a software update in a flock camera. If so maybe it could brick all the flock cameras it can connect to.

Linux 3.x has a lot of CVEs filed against its Bluetooth implementation.

Does the image have bluetooth stack ? There is no reason to include bluetooth stack into the build.

Re: Hackers Got Inside a Flock Camera

#247

I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on. (The above should not be read as supporting Flock or discouraging furt…

>“Who’s a good boy?!”

That a good watchdog kick message NGL.

Re: Hackers Got Inside a Flock Camera

#248

Earlier quoted context omitted.

Interesting that you frame it as "hoping" for a dystopia. Like even in our wildest imaginations we can't envision a future where society works for regular folks.

I'm sympathetic to the problem that folks like Mark Fisher have laid out, in which (to paraphrase) "it is easier to imagine the end of the world than the end of capitalism", and that indeed might be one way to understand my feeling. I take your point; it makes sense. "Regular folks" is doing a lot of work, though. It may very well be the case that most of the material world which props up the idea of "regular folks"…

Damn, calling out Mark Fisher and Pat the Bunny? I think we are immersed in a lot of the same cultural and intellectual movements.

Re: Hackers Got Inside a Flock Camera

#249
post #152

Earlier quoted context omitted.

Because software engineering is not professional engineering. Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult.

Do you feel like an inadiquate imposter or something? I'm assuming you work in software. Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design. Or read about engineering failures like flight QF32 (mostly a success story): A paperwork review showed that the required signatures were missing from 131 out of 138 retro…

>Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems.

I mean, you make my point. At no point did I say engineers are the only required component, but without the responsibility of an engineer signing off on its technical adequacy we have loads of historical proof that people end up dead far more often.

Re: Hackers Got Inside a Flock Camera

#250
post #39

> According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454. Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plat…

The default retention policy is 7 days and the local customer (IE the police) can set it to whatever.

I wonder what can be done within 3 minutes?

Post reply on HN