Earlier quoted context omitted.
Yep. Clown show. > The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took. > I…
How could anyone possibly physically access a device that is just sitting out in public?
Hackers Got Inside a Flock Camera
121–130 of 270 posts
Re: Hackers Got Inside a Flock Camera
#122I wonder what would happen if one of their customers asked for a 62443-4-2 certificate of compliance?
Re: Hackers Got Inside a Flock Camera
#123Earlier quoted context omitted.
The question is, why should they care at all? Will this hurt their business?
Any breach of security on a system like this is a big flashing red-alert to me. If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated. Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.
Overall this goes from disappointing to fairly repugnant.
Re: Hackers Got Inside a Flock Camera
#124Re: Hackers Got Inside a Flock Camera
#125This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. U…
The question is, why should they care at all? Will this hurt their business?
Re: Hackers Got Inside a Flock Camera
#126The article says that Flock says "their cameras don't do facial recognition" The cameras don't, but they don't say the system doesn't. They don't say facial recognition isn't a click away through another integration. I would absolutely assume that any system that sends your image to LE is part of a facial recognition system in practice. We know now that the cameras do recognize people and intentionally transmits imag…
edit: And to be clear, the cameras specifically recognize and record people for a reason. This does not appear to be a fault in the system. One reason might be off-camera facial recognition.
Re: Hackers Got Inside a Flock Camera
#127Re: Hackers Got Inside a Flock Camera
#128This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577 Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera
I poked around in the boot partition. The kernel is ancient! Linux version 3.18.71-perf-gaf770dc
missing a d(gaf)
sorry, had to get that out!
Re: Hackers Got Inside a Flock Camera
#129This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. U…
It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.
Re: Hackers Got Inside a Flock Camera
#130This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. U…
If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.