Hackers Got Inside a Flock Camera
driverdan
510 points
233 comments
September 16, 2026
https://micahflee.com/flock-cameras-are-riddled-with-securit...
Related Discussions
Found 5 related stories in 67.6ms across 6,833 title embeddings via pgvector HNSW
- Hackers Stole Flock Camera Software Revealing How Company Tracks Cars and People driverdan · 34 pts · September 16, 2026 · 81% similar
- Flock cameras are riddled with security vulnerabilities and hardcoded creds micahflee · 44 pts · September 16, 2026 · 77% similar
- Flock (Again) Activates a Camera System a Town Had Voted to Shut Down hn_acker · 58 pts · August 13, 2026 · 67% similar
- 90k Flock cameras have gone up in the US: What they track and how to check CrankyBear · 17 pts · July 21, 2026 · 66% similar
- I Reported on Flock's Cameras. Now I'm One of the System's Mistakes CharlesW · 50 pts · July 23, 2026 · 65% similar
Discussion Highlights (20 comments)
driverdan
This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577 Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera
client4
https://archive.vn/NiIzH
ck2
so when do we get it flipped to a nationwide bird migration tracking system? as someone pointed out: let's make that "flock" name accurate also make it identify bird song, I am sure there are microphones on there
smalltorch
>At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!
iamnothere
I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on. (The above should not be read as supporting Flock or discouraging further investigation.) > The camera’s logs also show the camera struggling with storage. Its logs recorded more than 27,000 “no space left on device” errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots. At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs. Lol
drfloyd51
So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.
goolz
Why did we not get the cool dystopia ala Gibson's Chiba City?
deaux
Title is missing "(YC S17)" after "Flock".
hk1337
I feel like most of this was already known when someone here in Dallas figured out they had wifi connectivity you could connect and get access. I may not have the details exactly correct but I think someone got access then.
ohyoutravel
Flock is a scourge on democracy. Flock is YC. But looks like they did YC nearly ten years ago. Who knows what their pitch deck looked like? If they pivoted since then to their current sinister incarnation? I don’t see any evidence that YC is still actively supporting them. Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable proposition than funding Flock for their current use case of allowing police to stalk their ex girlfriends or mistresses.
zzzeek
If I had to guess now it works it would be: 1. Take pictures 2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes Did I miss something
petcat
> According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454. Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1]. [1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes
writtenone
A friend in China built a Flock overlay network that sends live video and audio from ~100 cameras near me to an AWS server for processing and search.
ktm5j
> "We liberated hardware" Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.
thangalin
https://i.ibb.co/WWWYznHX/flock-future.png ;-) See also: https://dave.autonoma.ca/blog/2019/06/06/web-of-knowledge/
killbot5000
This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access. Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
wilburTheDog
I wonder if a stingray could be used to force a software update in a flock camera. If so maybe it could brick all the flock cameras it can connect to.
vayup
If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP. They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay. Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested. And also, infrastructure vulnerabilities like DNS config - no no, try harder. I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair. https://www.flocksafety.com/legal/vulnerability-disclosure-p...
inanutshellus
Curious how/why all this negative attention is focused directly on the Flock brand (current example notwithstanding)? Seems like if I were a competitor of Flock I'd be pretty happy right now and all this negative press is making them artificially cheap to buyout right now. Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this level of attention... not on the overarching issue of surveillance-state-ing, but of one particular company.
anguishe
I wonder if they were able to find any of the Bluetooth signal-data these cameras are said to be obtaining from devices within its' vicinity. This in itself is wild, im glad they're coming down around where I am