Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

261–270 of 270 posts

Re: Hackers Got Inside a Flock Camera

#261

Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have bee…

Exactly. The scary part isn't any single bug, it's the mismatch between the sensitivity of the system and the apparent security model

Re: Hackers Got Inside a Flock Camera

#262

Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have bee…

I too am appalled by the inefficiencies of the bureaucracy of the Gestapo. A serious threat to the state and the people could take days to reach the correct authorities. Only zhast month a smuggler escaped zhe guards, no doubt an agent of foreign intelligence.

I get the joke, but this is kind of why the security issue matters

Re: Hackers Got Inside a Flock Camera

#263
post #105

If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP. They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY ca…

> Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.

> And also, infrastructure vulnerabilities like DNS config - no no, try harder.

It's understandable. If you have or manage a website you will receive daily emails (the kind that start with 'Hello sir') about automated scans finding low-hanging fruits like that, pretending a bounty payment.

Re: Hackers Got Inside a Flock Camera

#264

Earlier quoted context omitted.

You'd be surprised how many things you use daily that people still backport the bare minimum to clig to 2.4.x forever

I really hope those don't have access to any networks.

good chance the linux running in your high end phone's modem runs 2.x kernel.

i dont deal with that anymorrle, but last one I saw with 2.x was the pixel 6 pro.

Re: Hackers Got Inside a Flock Camera

#265

Earlier quoted context omitted.

I really hope those don't have access to any networks.

good chance the linux running in your high end phone's modem runs 2.x kernel. i dont deal with that anymorrle, but last one I saw with 2.x was the pixel 6 pro.

Just check, my 2YO phone runs kernel 6.6, not latest but i think good enough for production.

Edited: I misunderstood what you mean, you were talking about the modem subsystem, sorry.

Re: Hackers Got Inside a Flock Camera

#266

Earlier quoted context omitted.

I say these people should not be in charge of choosing who gets insane amounts of money and networking opportunities

They should not be in charge of anything, but being a sociopath gets you obscene amounts of money and puts you in charge of all sorts of things.

I wish this was just an anecdote rather than an axiom.

Re: Hackers Got Inside a Flock Camera

#269

I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on. (The above should not be read as supporting Flock or discouraging furt…

Cisco sells IP connected high def cameras. I was happy to stop working on that project, because it was clear that the target market was public facial recognition (targeted advertisement in malls, and other useless/creepy things).

Re: Hackers Got Inside a Flock Camera

#270

Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have bee…

I for one welcome the incompetence. Godspeed to whoever is able to deploy a build to the whole device fleet that burns SoM boot protection fuses to an image that doesn't do anything hard bricking their entire network.

oversights like these are what eventually lead to situations like in 'Watch Dogs' and 'Cyberpunk' where you have these one click exploit that can break every tech and surveillance gadget in sight
Post reply on HN