has been for a long time - there's a sound engineer who developed quite a following (and is fairly involved with local movement hackerspaces) who demo'd how easy it was to hack Flock cameras nearly a year ago: https://www.youtube.com/watch?v=uB0gr7Fh6lY
> The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.
> In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.
But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?
A network connected device that can be hacked is a small step away from being the first foothold into its server. The fact that on-device security is this atrocious suggests that their server is not any better quality, which means hacking it would probably not take much effort.
Is this an older model? I could see them turning off or using weak encryption on media if the hardware couldn't keep up with the amount of data they were writing.
I'm in the process of optimizing a bootolader for my various SoC/SBCs and even the cheapest, oldest least powerful SoC from 15 years ago can manage AES-CBC via crypto accelerator at 50 MiB/s. There's no excuse.
You can achieve 50MiB/s if that's all that you're doing. I've worked with some DSPs (TI's DaVinci line) where some operations would abort if DDR was overwhelmed.
For example, passing a frame of video (YUV) into the peripheral which can resize the overall image, would fail if the system was busy with other DMA transfers. You could attempt to resize again, but there were no guarantee that it would complete successfully. Your options are to reduce overall DDR utilization or drop frames. In an application like Flock's, dropping frames is likely something they need to avoid.
The system in question is doing similar tasks, and I don't think that what I'm suggesting is out of the question.
> According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454.
Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1].
[1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes
3.18.71-perf-gaf770dc is a Qualcomm Android vendor kernel from roughly late 2017. The 3.18 branch went fully EOL in 2019, so nothing after that was ever backported to it.
same, but i'm not sure how that's related to my comment. workarounds or alternate articles without significant new information are typically posted within the same submission, not separate ones.
They won’t have that sort of moment of self reflection until someone does something like use Flock infrastructure to stalk and assassinate the CEO of another YC company and then it will only be brief and fleeting before they double down on supporting this kind of egregious behaviour.
I feel like most of this was already known when someone here in Dallas figured out they had wifi connectivity you could connect and get access. I may not have the details exactly correct but I think someone got access then.
That's also the biggest plot-hole in the first Star Wars movie. Princess Leia is supposed to be this righteous noble of the moral resistance and yet she STEALS the Death Star plans!
I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on.
(The above should not be read as supporting Flock or discouraging further investigation.)
> The camera’s logs also show the camera struggling with storage. Its logs recorded more than 27,000 “no space left on device” errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots. At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs.
"Axon is Flock but worse" will be the next big fight as police departments are pulling a fast one and saying "we got rid of Flock" by switching to Axon.
Axon (among others) has operations hubs for data fusion centers and other platforms for police like Evidence.com, so it’s an easy sell to departments.
Communities are starting to pivot to the wider issue, but a reason that this issue found purpose is that Flock is a more evocative target than “ALPRs”. I think it wouldn’t be a bad thing if “Flock” becomes the generic name.
Axon is the default for the on-body camera system. The barrage of cop tv shows use them as part of their promotional relationships. Flock decided to not attack their market, in stead go for the adjacent space.
While Axon's system should be under the microscope too I don't think they have the nation wide cloud that Flock is doing and requires specific agreements to share data. Maybe that is getting abused to form a national database but I imagine it was designed so say a county sheriff department and local city PDs could share resources. I don't think most people are that concerned about things like that (though they should be), it is the nation wide surveillance that creeps people out. That and the stalking of course and both systems can be used for that.
Axon and Motorola also do a lot more to court state agencies who have grand plans of monitoring some highway corridor so their buddies at DEA/CPB/SMD/whatever can tip them off and their "drug task force" can make a newsworthy bust.
Flock by contrast courts local PDs who will catch a package thief or two but they really just want to have the drag net at their finger tips so that when some more equal animal's cat gets stolen they can walk back in time and figure out the short list of who could've done it.
For those unaware, embedded devices usually have a "watchdog" timer that needs to be periodically reset ("fed"/"pet"/"kicked") when everything is operating correctly or else the device will reboot as a fail-safe.
This log message probably indicates when they're resetting the watchdog timer.
Also, a reminder that ALPR abuse predates Flock. Flock has just made it more visible. About a decade ago I personally heard a cop let it slip that he had plate-stalked someone for the crime of saying mean things about his department on Twitter. The difference today is that more departments have access to these kinds of tools.
Fixed ALPRs aren't the only privacy problem, either. Many tow trucks have roving ALPRs that feed into big databases. The notion is that it helps them repossess cars that might be garaged at home. That data, however, is for sale to third parties.
Flock is a scourge on democracy. Flock is YC. But looks like they did YC nearly ten years ago. Who knows what their pitch deck looked like? If they pivoted since then to their current sinister incarnation? I don’t see any evidence that YC is still actively supporting them.
Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable proposition than funding Flock for their current use case of allowing police to stalk their ex girlfriends or mistresses.
Yes. Blame the pickaxe seller. Do not question the miners. Do not question the investors in the mining companies. Do not question the casual member population who thinks that all this is fine.
This isn't to say that flock not a scourge, but I think a lot of people (not saying you're one of them) could stand to look in the mirror here.
Back in ye olde dark ages of <checks notes> 2017, when YC was cutting Flock a check and when "big data" was the hot buzzword people of a certain bent couldn't get enough of this kind of stuff. Everyone was jacking off nonstop to the idea that we could just hoover up everyone's data ad then "efficiently" or "proactively" dispatch enforcement resources. People talked all sorts of big talk about stuff like cross referencing people's Home Depot spend with permit requirements, identifying small businesses that don't have healthy enough financials to be fully compliant, cross referencing invoices and delivery receipts to identify overloaded trucks, and generally finding all sorts of ways to fine the crap out of people for the pettiest of petty deviance. They considered this a noble goal.
Everyone's head was too far up their asses to look at the magic crystal ball called "history" and realize that a camera on every street corner watching who's going where all the damn time would be where it goes.
It’s not like this stuff wasn’t known to be a problem 10 years ago. We were already in Trump’s first term, it’s not like it was part of the early post 9/11 “secure everything” push. It was WAY after that.
It’s not an excuse, but gives some luxury of distance. We have a lot more hindsight now on how rotten things can become, so with that hindsight it’s easy to say that companies like Flock shouldn’t exist, or shouldn’t be invested in. Ten years ago required some more leaps in foresight that some people were making, I was, but even I didn’t think it would get as evil as it has.
They just had a Superbowl ad like two years ago (ok, it was for Ring, but partnering with Flock) that said it was all about finding lost dogs around the neighborhood...and, that was it.
The system they log into is called DAVID(Driver and Automobile Information Database) which logs activity. If an officer access that information for unlawful purposes, they can be prosecuted. You probably wont believe it, but the reason you hear about cops stalking their ex's is because they got caught doing so.
It’s not even suitably encrypted on device?
Zero trust in anything Flock says.
the Flock response has been 'it doesn't count if a Youtuber did it' lol: https://www.youtube.com/watch?v=0ADb-qQ5hMY
> The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.
> In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.
Source: https://www.404media.co/hackers-stole-flocks-camera-software...
But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?
For example, passing a frame of video (YUV) into the peripheral which can resize the overall image, would fail if the system was busy with other DMA transfers. You could attempt to resize again, but there were no guarantee that it would complete successfully. Your options are to reduce overall DDR utilization or drop frames. In an application like Flock's, dropping frames is likely something they need to avoid.
The system in question is doing similar tasks, and I don't think that what I'm suggesting is out of the question.
Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1].
[1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes
Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera
Linux version 3.18.71-perf-gaf770dc
Some people are just wired that way.
Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.
(The above should not be read as supporting Flock or discouraging further investigation.)
> The camera’s logs also show the camera struggling with storage. Its logs recorded more than 27,000 “no space left on device” errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots. At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs.
Lol
Communities are starting to pivot to the wider issue, but a reason that this issue found purpose is that Flock is a more evocative target than “ALPRs”. I think it wouldn’t be a bad thing if “Flock” becomes the generic name.
"Page 17" in the document shows a spicy little chip.
https://www.quectel.com/product/kg100s-amazon-sidewalk-modul...
Axon not only includes a cell modem... they're on Amazon Sidewalk, baby.
https://coverage.sidewalk.amazon/
Flock by contrast courts local PDs who will catch a package thief or two but they really just want to have the drag net at their finger tips so that when some more equal animal's cat gets stolen they can walk back in time and figure out the short list of who could've done it.
This log message probably indicates when they're resetting the watchdog timer.
Fixed ALPRs aren't the only privacy problem, either. Many tow trucks have roving ALPRs that feed into big databases. The notion is that it helps them repossess cars that might be garaged at home. That data, however, is for sale to third parties.
as someone pointed out: let's make that "flock" name accurate
also make it identify bird song, I am sure there are microphones on there
We'll call it Cock Safety and help our community with patented JimmyHat technology to keep you safe and covered.
Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable proposition than funding Flock for their current use case of allowing police to stalk their ex girlfriends or mistresses.
The front page then had "All the footage is yours. Your neighborhood 100% owns the data. Flock Safety will not share, sell, or access your data."
Unfortunately, flock has been excluded from wayback, so can't see other views of that page.
{insert Darth Vader: I'm altering the deal. Pray I don't alter it any further.}
Yes. Blame the pickaxe seller. Do not question the miners. Do not question the investors in the mining companies. Do not question the casual member population who thinks that all this is fine.
This isn't to say that flock not a scourge, but I think a lot of people (not saying you're one of them) could stand to look in the mirror here.
Back in ye olde dark ages of <checks notes> 2017, when YC was cutting Flock a check and when "big data" was the hot buzzword people of a certain bent couldn't get enough of this kind of stuff. Everyone was jacking off nonstop to the idea that we could just hoover up everyone's data ad then "efficiently" or "proactively" dispatch enforcement resources. People talked all sorts of big talk about stuff like cross referencing people's Home Depot spend with permit requirements, identifying small businesses that don't have healthy enough financials to be fully compliant, cross referencing invoices and delivery receipts to identify overloaded trucks, and generally finding all sorts of ways to fine the crap out of people for the pettiest of petty deviance. They considered this a noble goal.
Everyone's head was too far up their asses to look at the magic crystal ball called "history" and realize that a camera on every street corner watching who's going where all the damn time would be where it goes.
10 years ago is no excuse.
Is hacker news anti-dog now ?
1. Take pictures
2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes
Did I miss something