Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have bee…
Hackers Got Inside a Flock Camera
261–270 of 270 posts
Re: Hackers Got Inside a Flock Camera
#262Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have bee…
I too am appalled by the inefficiencies of the bureaucracy of the Gestapo. A serious threat to the state and the people could take days to reach the correct authorities. Only zhast month a smuggler escaped zhe guards, no doubt an agent of foreign intelligence.
Re: Hackers Got Inside a Flock Camera
#263If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP. They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY ca…
> And also, infrastructure vulnerabilities like DNS config - no no, try harder.
It's understandable. If you have or manage a website you will receive daily emails (the kind that start with 'Hello sir') about automated scans finding low-hanging fruits like that, pretending a bounty payment.
Re: Hackers Got Inside a Flock Camera
#264Earlier quoted context omitted.
You'd be surprised how many things you use daily that people still backport the bare minimum to clig to 2.4.x forever
I really hope those don't have access to any networks.
i dont deal with that anymorrle, but last one I saw with 2.x was the pixel 6 pro.
Re: Hackers Got Inside a Flock Camera
#265Earlier quoted context omitted.
I really hope those don't have access to any networks.
good chance the linux running in your high end phone's modem runs 2.x kernel. i dont deal with that anymorrle, but last one I saw with 2.x was the pixel 6 pro.
Edited: I misunderstood what you mean, you were talking about the modem subsystem, sorry.
Re: Hackers Got Inside a Flock Camera
#266Earlier quoted context omitted.
I say these people should not be in charge of choosing who gets insane amounts of money and networking opportunities
They should not be in charge of anything, but being a sociopath gets you obscene amounts of money and puts you in charge of all sorts of things.
Re: Hackers Got Inside a Flock Camera
#267Next headline: Flock declares Hacker News a terrorist organization.
Re: Hackers Got Inside a Flock Camera
#268Re: Hackers Got Inside a Flock Camera
#269I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on. (The above should not be read as supporting Flock or discouraging furt…
Re: Hackers Got Inside a Flock Camera
#270Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have bee…
I for one welcome the incompetence. Godspeed to whoever is able to deploy a build to the whole device fleet that burns SoM boot protection fuses to an image that doesn't do anything hard bricking their entire network.