Live data from Hacker News

Hackers Got Inside a Flock Camera

wired.com

71–80 of 268 posts

Re: Hackers Got Inside a Flock Camera

#71
post #31

Earlier quoted context omitted.

do the articles have significantly different information/coverage to warrant two submissions?

I can't read the Wired article because I'm only allowed three excerpts and 15 ads a day at Wired.com

Use the Bypass Paywalls Clean extension https://gitflic.ru/project/magnolia1234/bypass-paywalls-fire...

Re: Hackers Got Inside a Flock Camera

#72

Earlier quoted context omitted.

It is bad. But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?

A network connected device that can be hacked is a small step away from being the first foothold into its server. The fact that on-device security is this atrocious suggests that their server is not any better quality, which means hacking it would probably not take much effort.

I don't disagree.

But there is some old rule about, even the best security can fail if the device is physically accessible.

Re: Hackers Got Inside a Flock Camera

#73

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

> all that data is literally there for any unauthorized person to walk up and take it.

All that data about ... license plates if you're willing to steal/damage private property. Seems like it would be a lot easier to setup your own ALPR.

Re: Hackers Got Inside a Flock Camera

#74

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

Is this an older model? I could see them turning off or using weak encryption on media if the hardware couldn't keep up with the amount of data they were writing.

As another commenter pointed out, any cheapo ARM core from the last 10 years could do the job Flock needs it to do, as long as it has a (very cheap and common) crypto engine strapped to it.

But, a question for you: even if it was the case that the hardware was the limitation, isn't that also an indictment of Flock? Selling something that cannot exist securely within the bounds of current technology? Or, at a minimum, bad chip selection leading to a compromised design?

Re: Hackers Got Inside a Flock Camera

#75

Earlier quoted context omitted.

Yep. Clown show. > The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took. > I…

TDIL my homebuilt Plex media server is more strongly encrypted than a Flock Camera

so is my all-passwords.txt file on my desktop

Re: Hackers Got Inside a Flock Camera

#76
post #39

> According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454. Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plat…

That same NH law perhaps more importantly limits ALPR use to law enforcement officers.

[flagged]

Re: Hackers Got Inside a Flock Camera

#77
post #11

Why did we not get the cool dystopia ala Gibson's Chiba City?

I remember walking over a hill into a rave in the Utah desert that we'd set up and thinking that it actually was the cyberpunk dystopia that I had been hoping for.

That kind of stuff is around but maybe not evenly distributed or legible to large demographics.

Unfortunately, so is the rest of the vicious horrorshow, equally illegible and equally uneven in distribution.

Re: Hackers Got Inside a Flock Camera

#78
post #44

> "We liberated hardware" Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.

Anything becomes permissible when you believe yourself to be “on the right side of history.”

Re: Hackers Got Inside a Flock Camera

#79
post #10

I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on. (The above should not be read as supporting Flock or discouraging furt…

"Axon is Flock but worse" will be the next big fight as police departments are pulling a fast one and saying "we got rid of Flock" by switching to Axon.

I live near Durango, CO and this happened last week.

Re: Hackers Got Inside a Flock Camera

#80

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

Yep. Clown show. > The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took. > I…

How could anyone possibly physically access a device that is just sitting out in public?
Post reply on HN