Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

151–160 of 275 posts

Re: Hackers Got Inside a Flock Camera

#151

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

Yep. Clown show. > The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took. > I…

Runs Android. Has (wireless?) internet access.

It seems that some enterprising Jolly Roger could start running a public mesh net on top of them without Flock even noticing.

Re: Hackers Got Inside a Flock Camera

#152

This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. U…

I really hate how Product Managers somehow get to take the reins of engineering teams instead of having to sell them product ideas. It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.

Because software engineering is not professional engineering.

Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult.

Re: Hackers Got Inside a Flock Camera

#154
post #44

> "We liberated hardware" Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.

> You should be able to own that if you're going to do something like this.

Um, are you saying the hackers should admit they broke the law? Or that Flock should righteously own the data they collect?

Either way, I d/c. Flock cameras are probably insecure, and their data is potentially dangerous.

Bad laws exist, and following them may be prudent at times, but the act of following them isn't a moral imperative.

Re: Hackers Got Inside a Flock Camera

#155
post #36

If I had to guess now it works it would be: 1. Take pictures 2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes Did I miss something

The system they log into is called DAVID(Driver and Automobile Information Database) which logs activity. If an officer access that information for unlawful purposes, they can be prosecuted. You probably wont believe it, but the reason you hear about cops stalking their ex's is because they got caught doing so.

I don't care if a small amount of cops get in trouble if the other 99% of the time they get away with it.

Re: Hackers Got Inside a Flock Camera

#156

Earlier quoted context omitted.

The question is, why should they care at all? Will this hurt their business?

Any breach of security on a system like this is a big flashing red-alert to me. If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated. Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.

Getting persistent access to Flock's internal network is a high-priority item for every US adversary, who doesn't want free intel collection on the movements of persons of interest? Knowing who the FBI and local cops are monitoring in is the counter-counter-intelligence cherry on top of a self-inflicted dragnet surveillance cake.

Any entity with access to flock servers can virtually stake-out anyone/everyone driving past Flock camera to monitor their movements. In a hot war, this would provide actionable data to support assassination via road-side bomb/drone strikes.

Re: Hackers Got Inside a Flock Camera

#157

Earlier quoted context omitted.

The question is, why should they care at all? Will this hurt their business?

Any breach of security on a system like this is a big flashing red-alert to me. If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated. Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.

Many moons ago, I was involved in the technical side of volunteer work for domestic violence victims escaping abusive relationships with e.g. law enforcement (cops), who even fifteen years ago had sweeping powers to track and stalk their victims. Things like actual anonymous burner phones and the ability to e.g. create new email accounts without government identification were critical to the process of getting these people out safely, or alive, without fear of retaliation.

I can't even imagine how difficult this job must be nowadays, with bullshit like Flock spanning hundreds of police departments participating in their nationally-linked database. I have zero sources for what I'm about to say, but my instinct is that the political machines (expanding powers hidden behind "think of the children") behind how technology is evolving today has gotten people killed.

Re: Hackers Got Inside a Flock Camera

#159

Earlier quoted context omitted.

A network connected device that can be hacked is a small step away from being the first foothold into its server. The fact that on-device security is this atrocious suggests that their server is not any better quality, which means hacking it would probably not take much effort.

I don't disagree. But there is some old rule about, even the best security can fail if the device is physically accessible.

There are levels to defending against physical attacks, and Flock half-assed theirs by leaving the encryption key right on the file system, according to the reporting. Those more serious about security — like Apple — store keys in an "enclave" chip so it can't be easily extracted by an attacker doing the bare minimum

Re: Hackers Got Inside a Flock Camera

#160
post #44

> "We liberated hardware" Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.

But we own the cameras

No we don't, even if our taxes paid for them. You don't own public buildings either, that's not how it works.
Post reply on HN