Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

61–70 of 268 posts

Re: Hackers Got Inside a Flock Camera

#61

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

has been for a long time - there's a sound engineer who developed quite a following (and is fairly involved with local movement hackerspaces) who demo'd how easy it was to hack Flock cameras nearly a year ago: https://www.youtube.com/watch?v=uB0gr7Fh6lY

the Flock response has been 'it doesn't count if a Youtuber did it' lol: https://www.youtube.com/watch?v=0ADb-qQ5hMY

Re: Hackers Got Inside a Flock Camera

#62
post #30

I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on. (The above should not be read as supporting Flock or discouraging furt…

While Axon's system should be under the microscope too I don't think they have the nation wide cloud that Flock is doing and requires specific agreements to share data. Maybe that is getting abused to form a national database but I imagine it was designed so say a county sheriff department and local city PDs could share resources. I don't think most people are that concerned about things like that (though they should…

Axon and Motorola also do a lot more to court state agencies who have grand plans of monitoring some highway corridor so their buddies at DEA/CPB/SMD/whatever can tip them off and their "drug task force" can make a newsworthy bust.

Flock by contrast courts local PDs who will catch a package thief or two but they really just want to have the drag net at their finger tips so that when some more equal animal's cat gets stolen they can walk back in time and figure out the short list of who could've done it.

Re: Hackers Got Inside a Flock Camera

#63
post #33

I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on. (The above should not be read as supporting Flock or discouraging furt…

Also, a reminder that ALPR abuse predates Flock. Flock has just made it more visible. About a decade ago I personally heard a cop let it slip that he had plate-stalked someone for the crime of saying mean things about his department on Twitter. The difference today is that more departments have access to these kinds of tools. Fixed ALPRs aren't the only privacy problem, either. Many tow trucks have roving ALPRs that…

I work in a different embedded space but our keepalive heartbeat messages have a payload of <3

Re: Hackers Got Inside a Flock Camera

#64

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

Yep. Clown show. > The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took. > I…

TDIL my homebuilt Plex media server is more strongly encrypted than a Flock Camera

Re: Hackers Got Inside a Flock Camera

#65

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

It is bad. But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?

A network connected device that can be hacked is a small step away from being the first foothold into its server. The fact that on-device security is this atrocious suggests that their server is not any better quality, which means hacking it would probably not take much effort.

Re: Hackers Got Inside a Flock Camera

#66
post #32

Earlier quoted context omitted.

Is this an older model? I could see them turning off or using weak encryption on media if the hardware couldn't keep up with the amount of data they were writing.

I'm in the process of optimizing a bootolader for my various SoC/SBCs and even the cheapest, oldest least powerful SoC from 15 years ago can manage AES-CBC via crypto accelerator at 50 MiB/s. There's no excuse.

You can achieve 50MiB/s if that's all that you're doing. I've worked with some DSPs (TI's DaVinci line) where some operations would abort if DDR was overwhelmed.

For example, passing a frame of video (YUV) into the peripheral which can resize the overall image, would fail if the system was busy with other DMA transfers. You could attempt to resize again, but there were no guarantee that it would complete successfully. Your options are to reduce overall DDR utilization or drop frames. In an application like Flock's, dropping frames is likely something they need to avoid.

The system in question is doing similar tasks, and I don't think that what I'm suggesting is out of the question.

Re: Hackers Got Inside a Flock Camera

#67

Earlier quoted context omitted.

Is this an older model? I could see them turning off or using weak encryption on media if the hardware couldn't keep up with the amount of data they were writing.

That would be an extremely bad trade.

Why? Does Flock really care about encryption? It checks off a box for their sales team, even if it's done poorly.

Re: Hackers Got Inside a Flock Camera

#68
post #21

Title is missing "(YC S17)" after "Flock".

Correct. YC gotta wear their creations with pride.

They won’t have that sort of moment of self reflection until someone does something like use Flock infrastructure to stalk and assassinate the CEO of another YC company and then it will only be brief and fleeting before they double down on supporting this kind of egregious behaviour.

Some people are just wired that way.

Re: Hackers Got Inside a Flock Camera

#69
post #36

If I had to guess now it works it would be: 1. Take pictures 2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes Did I miss something

The system they log into is called DAVID(Driver and Automobile Information Database) which logs activity. If an officer access that information for unlawful purposes, they can be prosecuted. You probably wont believe it, but the reason you hear about cops stalking their ex's is because they got caught doing so.

How many didn't get caught? Or did but the issue was quietly "handled" within the department.
Post reply on HN