- cross-posted to:
- [email protected]
- cross-posted to:
- [email protected]
Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them.
The breach provides an unprecedented look inside a system that Flock has described as protected by on-device encryption. The hackers were able to copy the camera’s storage and recover an encryption key stored on the device, which unlocked videos of thousands of vehicle detections. The hackers shared the material with 404 Media and the transparency nonprofit Distributed Denial of Secrets, which shared the data with WIRED. 404 Media and WIRED then analyzed those files as part of a joint investigation.
While much of the automatic license plate reader’s most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag.
Maybe I’m out of the loop but storing an encryption key on the encrypted device itself seems like bad opsec. Or I’ve misunderstood the article
It sounds like Flock fucked up. A camera shouldn’t have keys to decrypt videos. Maybe they were using symmetrical encryption rather than having the camera encrypt the videos using a public key.
This. You’d definitely want the cameras to have only the public key. If they’re not doing that, then their security must be as bad as their morals because they know people are tearing these down everywhere already anyway.
Of course, not using assymetric encryption makes them more auditable by “third parties” which is an unexpected benefit.
I wonder if they at least use a different key per camera. This would be less necessary for asymmetric encryption, of course, but they don’t seem to be using it. If all the cameras are using the same key, then you can theoretically use the key these people pulled to access data on every other camera as well (possibly remotely if you can remote in somehow).
Remote in somehow? Considering they’re apparently quite simple to access, I imagine it’s not all that complicated to add a bit of clever inside the casing to facilitate remote access. Still, that’s a small number of them —unless that was shared too, of course. 😉
Yet again, incompetence being the only thing saving us from fully entrenched fascism
Hey hackers, please for the love of PRIMUS, somebody hack the feds and release the Epstein files.
If you run up against Wired’s paywall, there is a link in the first, readable paragraph to 404 Media’s openly available article, based on a joint analysis of the hacked Flock material.
Vibe coding and AI slop is bringing back havktivism. Hell yea.







