Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

251–260 of 270 posts

Re: Hackers Got Inside a Flock Camera

#251
post #177

Earlier quoted context omitted.

- Camera takes picture - Camera pre-checks the picture for quality and that there's something on there that they want - Camera uploads picture to flock servers - Camera deletes picture locally - Rinse and repeat I could actually see this being done by three jobs in parallel. If there are a lot of images found on the camera then that's probably because the upload wasn't able to keep up with the amount of data that was…

It sounds like this whole thing is just in violation of New Hampshire state law.

But was this in New Hampshire? The retention policy is set by the customer.

Re: Hackers Got Inside a Flock Camera

#252

Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have bee…

I for one welcome the incompetence. Godspeed to whoever is able to deploy a build to the whole device fleet that burns SoM boot protection fuses to an image that doesn't do anything hard bricking their entire network.

Re: Hackers Got Inside a Flock Camera

#253

All these cameras do is pre-select the images that are worthy uploading. Everything else happens at Flock. That's why they don't give anything about the camera's security. The images are all from a public place, so no privacy expectations and what's theworst that could happen? Someone uploads their cat images or the pr0n collection? Ai figures that one out rather quickly.

Assuming the point of these cameras is security (and not just surveillance for stalker cops), being able to upload replacement footage would subvert that entirely. This has been a feature of many spy and cops/robber movies.

How would uploading bad footage negatively effect people trying to find license plates? It's not deleting the footage they are looking for.

Re: Hackers Got Inside a Flock Camera

#254

Earlier quoted context omitted.

Assuming the point of these cameras is security (and not just surveillance for stalker cops), being able to upload replacement footage would subvert that entirely. This has been a feature of many spy and cops/robber movies.

The point of these cameras is to deliver as many images of good quality as possible that show something of interest like a person, a car's numberplate and so on. I almost guarantee you, if the camera even has a SIM-Card then it's pre-configured with all the necessary information to find and join the mobile core network via APN. It turns on, joins the core network, gets handed an ip address and additional information…

[dead]

Re: Hackers Got Inside a Flock Camera

#255

A friend in China built a Flock overlay network that sends live video and audio from ~100 cameras near me to an AWS server for processing and search.

This is an interesting claim since their cameras dont seem to capture video. Just still images.

Re: Hackers Got Inside a Flock Camera

#256
post #235
post #225

Earlier quoted context omitted.

Only a handful of states have any concept of a recall election.

Exactly. It helps they also control who can even run for office in any meaningful way. Nobody fights the left harder than Democrats. Good luck finding a representative that is against data centers, flock, Israel, congressional stock bans and pausing and regulating AI, views overwhelming popular with the majority of the actual American public.

>Good luck finding a representative that is against data centers, flock, Israel, congressional stock bans and pausing and regulating AI, views overwhelming popular with the majority of the actual American public.

That is rapidly becoming Democratic party orthodoxy. At the very least there are a sizable number of Democrats who fit that.

Re: Hackers Got Inside a Flock Camera

#257
post #105

If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP. They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY ca…

This looks like a pretty reasonable policy to me all things considered. And no, I'm no fan of Flock. But they do run security cameras for the cops, they can't just say go ahead, go wild on all our customers' cameras. The lawyers would throw a fit. The carveouts for stuff like configuration and DNS are entirely reasonable. Have you ever been behind a security@ email before? You get a lot of BS reports of that sort.

Why can't Flock do a "customer setup" that is otherwise sandboxed from their systems and let the white hats go nuts on that?

Content is not the same as configuration and they could get valuable information if they cared.

Re: Hackers Got Inside a Flock Camera

#259
post #249

Earlier quoted context omitted.

Do you feel like an inadiquate imposter or something? I'm assuming you work in software. Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design. Or read about engineering failures like flight QF32 (mostly a success story): A paperwork review showed that the required signatures were missing from 131 out of 138 retro…

>Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems. I mean, you make my point. At no point did I say engineers are the only required component, but without the responsibility of an engineer signing off on its technical adequacy…

You believe signatures by engineers matter.

That is your belief, but I've never seen that belief backed by fact.

Most open source software disowns liability in CAPS in the license. Yet somehow FOSS like Linux gets used for safety critical infrastructure.

Microsoft would love certification requirements for engineers - that would kill open source to their conpetitive benefit.

Do you honestly think if we required Microsoft Certified Professionals to sign the internals of Microsoft OS then Windows would be more secure or reliable?

The bigger issue is that signatures and criminal consequences hardly matter across jurisdictions.

The capitalist issue is that businesses want scapegoats when things go wrong. That would be the outcome of signatures: engineers as fallboys for systemic failures across organisations.

Note how often pilots are blamed for accidents due to the design of planes.

It is just an idealistic belief based on feelies that software certification would achieve the goals you imagine it would.

Signatures are an anachronism: from an alien past.

International business uses different mechanisms for safety.

Our world is intertwined complexity. You somehow think that the buck should stop at engineers?

If engineers signed off on everything then we'd have no more disasters like New Orleans floods?

Who signed what for the Grenfell towers tragedy? Which engineers were reprimanded? Did they decide that more signatures would help prevent future disasters?

Post reply on HN