Hackers Got Inside a Flock Camera
Hackers who obtained and reverse engineered a Flock Safety license-plate reader found an outdated Android kernel, weak or missing on-device encryption, and hardcoded secrets that could expose stored images and potentially broader systems. Commenters argue this confirms fears about a poorly secured, privately run mass-surveillance network that tracks not just plates but vehicles, people, and even political bumper stickers, with high potential for police abuse, stalking, and secondary misuse. Many broaden the critique to venture-backed policing tech and competing vendors, questioning the ethics, oversight, and long-term democratic implications of ubiquitous automated surveillance infrastructure.
Outdated and Insecure Camera System
- Boot partition shows an Android/Linux 3.18 vendor kernel from ~2017, long out of support; commenters see this as indicative of serious neglect and missing years of security patches.
- Partition images reveal unencrypted sections (“vendor”, “media”) and encryption keys stored on-device; critics call this “clown show” key management and essentially no defense against physical access.
- Logs show huge numbers of “no space left on device” errors, crashes, and reboots, plus a watchdog heartbeat log message (“Who’s a good boy?!”), which some find amusing but also unprofessional.
- Hardcoded or quasi-hardcoded credentials/API keys and weak device enrollment are viewed as signs of poor security engineering and threat modeling, especially for hardware deployed in public.
- Debate over whether hardware constraints could justify weak on-device encryption; several embedded engineers argue even very cheap SoCs can handle proper crypto, so this is a design failure, not a necessity.
On-Device vs Cloud Risk
- Some argue a single compromised camera yields limited value versus the aggregate cloud dataset; others respond that physical compromise often leads to server compromise and that on-device data already contains sensitive imagery.
- The device appears to prefilter and upload images, including people, vehicles, bumper stickers, and decals, contradicting earlier marketing that implied only plates and minimal retention.
- Questions raised about compliance with strict retention laws (e.g., New Hampshire’s 3‑minute rule); situation viewed as likely non-compliant but ultimately “unclear” without more specifics.
Surveillance, Abuse, and Competitors
- Many see Flock as part of a broader ALPR/mass-surveillance ecosystem enabling stalking, domestic violence, over-policing, immigration raids, and data fusion with other police systems.
- Commenters stress that abuse of ALPRs predates Flock and that competitors (Axon, Motorola, Rekor, etc.) operate similar or worse systems, but Flock gets outsized attention due to market share and branding.
VC, YC, and Ethics
- Strong criticism of investors and accelerator backing: lack of technical due diligence, indifference to civil liberties, and a business model built on “surveillance as a service.”
- Early marketing promises (“community-owned data, no sharing”) are contrasted with current nationwide law-enforcement–centric usage; seen as a bait-and-switch enabled by venture incentives.
Responses, Policy, and Activism
- Calls for regulation of IoT security, adherence to standards (e.g., industrial cybersecurity certs), and stronger local political action (ordinances, contract termination, recalls).
- Some endorse direct action against cameras; others argue that violent or extra-legal responses would worsen the situation and that remaining democratic mechanisms should be used instead.