Hackers Cracked a Flock Camera and Found 1.6 Million Images in 21 Days
Hackers Got Inside a Flock Camera. Its Data Shows How the System Works

A hacker collective pulled down a Flock license plate reader and dumped its data, revealing thousands of videos and logs. The files show the device captured 1.6 million images of 50,000 vehicles in just 21 days, offering a rare look at how the surveillance system really works.
While the Flock camera itself does not perform facial recognition, likely due to its limited processing power, it transmits images to the server, which can then perform facial recognition.
- vayup
If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP.
They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay.
Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.
And also, infrastructure vulnerabilities like DNS config - no no, try harder.
I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair.
https://www.flocksafety.com/legal/vulnerability-disclosure-p...
- killbot5000
This is pure laziness aka “reduced time to market” on the part of Flock.
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
- drfloyd51
So… all that data is literally there for any unauthorized person to walk up and take it.
It’s not even suitably encrypted on device?
Zero trust in anything Flock says.
- driverdan
This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577
Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera
- petcat
> According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454.
Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1].
[1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes
- crumpled
The article says that Flock says "their cameras don't do facial recognition"
The cameras don't, but they don't say the system doesn't. They don't say facial recognition isn't a click away through another integration.
I would absolutely assume that any system that sends your image to LE is part of a facial recognition system in practice. We know now that the cameras do recognize people and intentionally transmits images of them, for later identification.
- writtenone
A friend in China built a Flock overlay network that sends live video and audio from ~100 cameras near me to an AWS server for processing and search.
- inanutshellus
Curious how/why all this negative attention is focused directly on the Flock brand (current example notwithstanding)?
Seems like if I were a competitor of Flock I'd be pretty happy right now and all this negative press is making them artificially cheap to buyout right now.
Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this level of attention... not on the overarching issue of surveillance-state-ing, but of one particular company.