Flock cameras are riddled with security vulnerabilities and hardcoded creds
micahflee
44 points
6 comments
September 16, 2026
Related Discussions
Found 5 related stories in 68.2ms across 6,833 title embeddings via pgvector HNSW
- Hackers Got Inside a Flock Camera driverdan · 510 pts · September 16, 2026 · 77% similar
- Hackers Stole Flock Camera Software Revealing How Company Tracks Cars and People driverdan · 34 pts · September 16, 2026 · 69% similar
- Despite Updates, Flock's Creepy Cameras Remain Major Civil Liberties Threat cdrnsf · 11 pts · August 13, 2026 · 65% similar
- 90k Flock cameras have gone up in the US: What they track and how to check CrankyBear · 17 pts · July 21, 2026 · 63% similar
- Flock CEO Admits Flock Is Used to Stalk People jhonovich · 14 pts · August 18, 2026 · 62% similar
Discussion Highlights (3 comments)
zeech
Discussion about the article this post is talking about: https://news.ycombinator.com/item?id=49726586
asveikau
tldr from my skim, the two worst things: * Probably vulnerable to CVEs that were patched in 2018 and 2021. * Generates API key to phone home based only on its own MAC address.
autoexec
Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have been enough vulnerabilities found in Flock's systems that it's pretty clear they aren't concerned about their security and it's plainly obvious that they don't care at all about our privacy or security. Even if we decided that this level of mass surveillance on the American public was acceptable to us, Flock Safety/Flock Group as already demonstrated that they can't and shouldn't be trusted to implement it.