If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP. They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY ca…
The TLS/SSL and DNS carveouts are pretty normal. There are a million security options for those services and enabling them all would often mean denying access to anyone running a browser/client more than a few weeks old. Documenting them all would be a PITA so most policies simply prohibit them entirely. Testing against customers is also a common prohibition for obvious reasons.
Hackers Got Inside a Flock Camera
241–250 of 270 posts
Re: Hackers Got Inside a Flock Camera
#242Earlier quoted context omitted.
Any breach of security on a system like this is a big flashing red-alert to me. If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated. Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.
Getting persistent access to Flock's internal network is a high-priority item for every US adversary, who doesn't want free intel collection on the movements of persons of interest? Knowing who the FBI and local cops are monitoring in is the counter-counter-intelligence cherry on top of a self-inflicted dragnet surveillance cake. Any entity with access to flock servers can virtually stake-out anyone/everyone driving…
https://edition.cnn.com/2026/08/26/us/flock-kentucky-police-...
A single cop can do it 2000 times it seems before they get caught
And it's not a lone case: https://www.washingtonpost.com/technology/2026/08/02/how-pol...
Re: Hackers Got Inside a Flock Camera
#243Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have bee…
Re: Hackers Got Inside a Flock Camera
#244So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.
I always assumed Flock's security posture was like most other companies. It's nice to see confirmation. I think I should add a "X'); DROP TABLE Cameras;--" bumper sticker to my car now. Couldn't resist: https://github.com/EvanAnderson/whimsy/blob/main/Drop_Table_...
Re: Hackers Got Inside a Flock Camera
#245Earlier quoted context omitted.
The oldest supported kernel is 5.10 and that loses support in December. That's wild they are using a 3.X kernel
You'd be surprised how many things you use daily that people still backport the bare minimum to clig to 2.4.x forever
Re: Hackers Got Inside a Flock Camera
#246I wonder if a stingray could be used to force a software update in a flock camera. If so maybe it could brick all the flock cameras it can connect to.
Linux 3.x has a lot of CVEs filed against its Bluetooth implementation.
Re: Hackers Got Inside a Flock Camera
#247I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on. (The above should not be read as supporting Flock or discouraging furt…
That a good watchdog kick message NGL.
Re: Hackers Got Inside a Flock Camera
#248Earlier quoted context omitted.
Interesting that you frame it as "hoping" for a dystopia. Like even in our wildest imaginations we can't envision a future where society works for regular folks.
I'm sympathetic to the problem that folks like Mark Fisher have laid out, in which (to paraphrase) "it is easier to imagine the end of the world than the end of capitalism", and that indeed might be one way to understand my feeling. I take your point; it makes sense. "Regular folks" is doing a lot of work, though. It may very well be the case that most of the material world which props up the idea of "regular folks"…
Re: Hackers Got Inside a Flock Camera
#249Earlier quoted context omitted.
Because software engineering is not professional engineering. Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult.
Do you feel like an inadiquate imposter or something? I'm assuming you work in software. Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design. Or read about engineering failures like flight QF32 (mostly a success story): A paperwork review showed that the required signatures were missing from 131 out of 138 retro…
I mean, you make my point. At no point did I say engineers are the only required component, but without the responsibility of an engineer signing off on its technical adequacy we have loads of historical proof that people end up dead far more often.
Re: Hackers Got Inside a Flock Camera
#250> According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454. Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plat…
I wonder what can be done within 3 minutes?