Hackers Got Inside a Flock Camera

driverdan 510 points 233 comments September 16, 2026
www.wired.com · View on Hacker News

https://micahflee.com/flock-cameras-are-riddled-with-securit...

Discussion Highlights (20 comments)

driverdan

This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577 Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera

client4

https://archive.vn/NiIzH

ck2

so when do we get it flipped to a nationwide bird migration tracking system? as someone pointed out: let's make that "flock" name accurate also make it identify bird song, I am sure there are microphones on there

smalltorch

>At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!

iamnothere

I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on. (The above should not be read as supporting Flock or discouraging further investigation.) > The camera’s logs also show the camera struggling with storage. Its logs recorded more than 27,000 “no space left on device” errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots. At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs. Lol

drfloyd51

So… all that data is literally there for any unauthorized person to walk up and take it. It’s not even suitably encrypted on device? Zero trust in anything Flock says.

goolz

Why did we not get the cool dystopia ala Gibson's Chiba City?

deaux

Title is missing "(YC S17)" after "Flock".

hk1337

I feel like most of this was already known when someone here in Dallas figured out they had wifi connectivity you could connect and get access. I may not have the details exactly correct but I think someone got access then.

ohyoutravel

Flock is a scourge on democracy. Flock is YC. But looks like they did YC nearly ten years ago. Who knows what their pitch deck looked like? If they pivoted since then to their current sinister incarnation? I don’t see any evidence that YC is still actively supporting them. Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable proposition than funding Flock for their current use case of allowing police to stalk their ex girlfriends or mistresses.

zzzeek

If I had to guess now it works it would be: 1. Take pictures 2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes Did I miss something

petcat

> According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454. Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1]. [1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes

writtenone

A friend in China built a Flock overlay network that sends live video and audio from ~100 cameras near me to an AWS server for processing and search.

ktm5j

> "We liberated hardware" Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.

thangalin

https://i.ibb.co/WWWYznHX/flock-future.png ;-) See also: https://dave.autonoma.ca/blog/2019/06/06/web-of-knowledge/

killbot5000

This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access. Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.

wilburTheDog

I wonder if a stingray could be used to force a software update in a flock camera. If so maybe it could brick all the flock cameras it can connect to.

vayup

If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP. They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay. Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested. And also, infrastructure vulnerabilities like DNS config - no no, try harder. I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair. https://www.flocksafety.com/legal/vulnerability-disclosure-p...

inanutshellus

Curious how/why all this negative attention is focused directly on the Flock brand (current example notwithstanding)? Seems like if I were a competitor of Flock I'd be pretty happy right now and all this negative press is making them artificially cheap to buyout right now. Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this level of attention... not on the overarching issue of surveillance-state-ing, but of one particular company.

anguishe

I wonder if they were able to find any of the Bluetooth signal-data these cameras are said to be obtaining from devices within its' vicinity. This in itself is wild, im glad they're coming down around where I am

Semantic search powered by Rivestack pgvector
6,833 stories · 62,541 chunks indexed