Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Small Programming Tricks(will-keleher.com ↗)
    62comments
  2. Dream-RSI: Recursive Self-Improvement through Evolving Worlds(arxiv.org ↗)
    31comments
  3. Mistral X Mozilla: Private, Multilingual AI Browsing(mistral.ai ↗)
    127comments
  4. Introducing System One Models and Jev(typesafe.ai ↗)
    461comments
  5. Tell the speakers that you liked their talks(ohhelloana.blog ↗)
    30comments
  6. Show HN: An e-ink frame that hears birds and draws them as 1800s illustrations(github.com/arnegiacomo ↗)
    223comments
  7. Claude Cowork and chat are now one Claude(claude.com ↗)
    69comments
  8. How big are factorials?(thegreenplace.net ↗)
    13comments
  9. Apple Reference Image: A New Approach for Verified Photography(security.apple.com ↗)
    292comments
  10. Hackers Got Inside a Flock Camera(wired.com ↗)
    140comments
  11. The Google Play app review process now regularly takes longer than a week(gultsch.social ↗)
    251comments
  12. Can we stop with the uptime percentages?(jim-nielsen.com ↗)
    56comments
  13. This Code Is CRAP (2011)(googleblog.com ↗)
    39comments
  14. Scaling Golang CI by Replacing actions/setup-go(cloudx.ai ↗)
    6comments
  15. Show HN: How Stale Is Your AI? Release age and training cutoff for 20 models(stale.jock.pl ↗)
    25comments
  16. Prisma's pgbouncer=true on Supabase made every query 4 round-trips (postmortem)(simbastack.com ↗)
    2comments
  17. Kyber (YC W23) Is Hiring a Forward Deployed Engineer(ycombinator.com ↗)
    discuss
  18. The DeepMind Institute(deepmind.com ↗)
    1comments
  19. Measuring Gauss-Seidel loop-carried dependency and fixing it via loop unrolling(loiseaujc.github.io ↗)
    3comments
  20. An update on Wayback Machine access(blog.archive.org ↗)
    339comments
  21. Original Sony PlayStation 2 security chip 'broken wide open' after 26 years(tomshardware.com ↗)
    53comments
  22. The Siberian Ice Maiden and the Scythian World(patrickwyman.substack.com ↗)
    discuss
  23. Salesforce Global Outage(salesforce.com ↗)
    135comments
  24. Show HN: I made a flight simulator, except you're just a passenger(inflightsimulator.com ↗)
    189comments
  25. Anatomy of a Texture(agentlien.github.io ↗)
    4comments
  26. Gemini 3.8 Live and 3.8 Live Extended Thinking(blog.google ↗)
    314comments
  27. Doing Everyone Else's Job(yosefk.com ↗)
    84comments
  28. Why I'm still bearish on LLMs after Navier-Stokes(dank.systems ↗)
    505comments
  29. Intelligence per Watt: Measuring Intelligence Efficiency of Local AI(arxiv.org ↗)
    44comments
  30. DeepSeek v4.1 Flash Is Now Our Best Hacking Model(enclave.ai ↗)
    42comments

Hackers Got Inside a Flock Camera

282 pointsby 4h agowired.com
139 comments
4h agoHN ↗

do the articles have significantly different information/coverage to warrant two submissions?

3h agoHN ↗

I can't read the Wired article because I'm only allowed three excerpts and 15 ads a day at Wired.com

2h agoHN ↗

same, but i'm not sure how that's related to my comment. workarounds or alternate articles without significant new information are typically posted within the same submission, not separate ones.

8m agoHN ↗

No, they're the same article. I had only read 404's when I submitted them and I assumed they'd both be submitted regardless.

3h agoHN ↗

I poked around in the boot partition. The kernel is ancient!

Linux version 3.18.71-perf-gaf770dc

3h agoHN ↗

The oldest supported kernel is 5.10 and that loses support in December. That's wild they are using a 3.X kernel

2h agoHN ↗

3.18.71-perf-gaf770dc is a Qualcomm Android vendor kernel from roughly late 2017. The 3.18 branch went fully EOL in 2019, so nothing after that was ever backported to it.

2h agoHN ↗

2017 was also the year Flock was funded and founded and went through the YConbinator cohort.

But you would have thought that by 2021 when Andreessen Horowitz funded them or at least by 2025 [1] when both further funded them, someone would have actually done some minor due diligence. Coincidentally too, 2025 was when the flock surveillance matrix went up all over the country almost immediately.

We constantly hear that the magic of tech funding lies in the people, not even the product/service. These types of things always seem to uncover that that is effectively just a lie to cover up the ulterior motives of setting up a tyrannical surveillance matrix all around you … to protect the children, of course.

[1] https://www.flocksafety.com/blog/flock-safety-secures-major-...

1h agoHN ↗

It's almost as if they paid a contractor to design the hardware back in 2017 and put all the funding into marketing(bribes) since then. Shocker.

48m agoHN ↗

gaf770dc

missing a d(gaf)

sorry, had to get that out!

3h agoHN ↗

so when do we get it flipped to a nationwide bird migration tracking system?

as someone pointed out: let's make that "flock" name accurate

also make it identify bird song, I am sure there are microphones on there

3h agoHN ↗

Someone should sell branded black trashbags with a spraypainted penis on them.

We'll call it Cock Safety and help our community with patented JimmyHat technology to keep you safe and covered.

3h agoHN ↗

At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!

3h agoHN ↗

I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also engaged in mass surveillance, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on.

(The above should not be read as supporting Flock or discouraging further investigation.)

The camera’s logs also show the camera struggling with storage. Its logs recorded more than 27,000 “no space left on device” errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots. At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs.

Lol

3h agoHN ↗

"Axon is Flock but worse" will be the next big fight as police departments are pulling a fast one and saying "we got rid of Flock" by switching to Axon.

3h agoHN ↗

Axon is the default for the on-body camera system. The barrage of cop tv shows use them as part of their promotional relationships. Flock decided to not attack their market, in stead go for the adjacent space.

2h agoHN ↗

Axon (among others) has operations hubs for data fusion centers and other platforms for police like Evidence.com, so it’s an easy sell to departments.

Communities are starting to pivot to the wider issue, but a reason that this issue found purpose is that Flock is a more evocative target than “ALPRs”. I think it wouldn’t be a bad thing if “Flock” becomes the generic name.

2h agoHN ↗

I live near Durango, CO and this happened last week.

1h agoHN ↗

This happened in a St. Louis suburb recently.

3h agoHN ↗

While highly unprofessional, the "Who's a good boy?!" status message makes me like them a tiny bit more

3h agoHN ↗

For those unaware, embedded devices usually have a "watchdog" timer that needs to be periodically reset ("fed"/"pet"/"kicked") when everything is operating correctly or else the device will reboot as a fail-safe.

This log message probably indicates when they're resetting the watchdog timer.

3h agoHN ↗

While Axon's system should be under the microscope too I don't think they have the nation wide cloud that Flock is doing and requires specific agreements to share data. Maybe that is getting abused to form a national database but I imagine it was designed so say a county sheriff department and local city PDs could share resources. I don't think most people are that concerned about things like that (though they should be), it is the nation wide surveillance that creeps people out. That and the stalking of course and both systems can be used for that.

2h agoHN ↗

Axon and Motorola also do a lot more to court state agencies who have grand plans of monitoring some highway corridor so their buddies at DEA/CPB/SMD/whatever can tip them off and their "drug task force" can make a newsworthy bust.

Flock by contrast courts local PDs who will catch a package thief or two but they really just want to have the drag net at their finger tips so that when some more equal animal's cat gets stolen they can walk back in time and figure out the short list of who could've done it.

3h agoHN ↗

Also, a reminder that ALPR abuse predates Flock. Flock has just made it more visible. About a decade ago I personally heard a cop let it slip that he had plate-stalked someone for the crime of saying mean things about his department on Twitter. The difference today is that more departments have access to these kinds of tools.

Fixed ALPRs aren't the only privacy problem, either. Many tow trucks have roving ALPRs that feed into big databases. The notion is that it helps them repossess cars that might be garaged at home. That data, however, is for sale to third parties.

2h agoHN ↗

I work in a different embedded space but our keepalive heartbeat messages have a payload of <3

2h agoHN ↗

Reminds me why a friend picked RCN over Comcast for his Internet. “They’re the more incompetent evil company.”

3h agoHN ↗

So… all that data is literally there for any unauthorized person to walk up and take it.

It’s not even suitably encrypted on device?

Zero trust in anything Flock says.

3h agoHN ↗

It is bad.

But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?

2h agoHN ↗

A network connected device that can be hacked is a small step away from being the first foothold into its server. The fact that on-device security is this atrocious suggests that their server is not any better quality, which means hacking it would probably not take much effort.

2h agoHN ↗

I don't disagree.

But there is some old rule about, even the best security can fail if the device is physically accessible.

1h agoHN ↗

i think this is actually good, because there are differences between the images they found, and security settings that the company claimed.

They had not admitted before to tracking people, but their software is clearly submitting them. They had not admitted before to looking at bumper stickers, but turns out they do.

I wonder if they could find all cars with Bernie Sanders bumper stickers within X blocks of a polling place.. I can imagine that (or similar queries) might be very useful in the wrong hands.

3h agoHN ↗

Is this an older model? I could see them turning off or using weak encryption on media if the hardware couldn't keep up with the amount of data they were writing.

3h agoHN ↗

That would be an extremely bad trade.

2h agoHN ↗

Why? Does Flock really care about encryption? It checks off a box for their sales team, even if it's done poorly.

2h agoHN ↗

Because data should be secure. Full stop.

1h agoHN ↗

If it increases development or operating costs by $1 they won't do it unless there are consequences that could cost them more than that.

1h agoHN ↗

In a perfect world, yes, but this is a for-profit company and there's almost zero repercussion for doing it half-assed. They'd have to pay someone to implement it, and deal with the overhead and complexity.

Now they are in a position where they can sell new models with enhanced encryption and more features.

3h agoHN ↗

I'm in the process of optimizing a bootolader for my various SoC/SBCs and even the cheapest, oldest least powerful SoC from 15 years ago can manage AES-CBC via crypto accelerator at 50 MiB/s. There's no excuse.

2h agoHN ↗

You can achieve 50MiB/s if that's all that you're doing. I've worked with some DSPs (TI's DaVinci line) where some operations would abort if DDR was overwhelmed.

For example, passing a frame of video (YUV) into the peripheral which can resize the overall image, would fail if the system was busy with other DMA transfers. You could attempt to resize again, but there were no guarantee that it would complete successfully. Your options are to reduce overall DDR utilization or drop frames. In an application like Flock's, dropping frames is likely something they need to avoid.

The system in question is doing similar tasks, and I don't think that what I'm suggesting is out of the question.

1h agoHN ↗

They can choose the SoC that would be able to fill the requirements. Eg. almost all Rockchip SoCs have NoC with configurable QoS on master ports (even the cheapest IP camera targetted SoCs that cost like 2-3$), or some other interconnect mechanism that can make it so that SDRAM controller gets tasks in some user selected priority order (eg. you deprioritize CPU in favor of camera interface and other things). This is not a new tech. It already existed when Flock was founded.

And in any case. Passing compressed video streams or pictures through HW encryption engine will not saturate 1.5+ GiB/s or whatever even the lousiest 16-bit DDR3 at 400MHz would give you, not even close. It would be like a fraction of a percent of total bandwidth.

1h agoHN ↗

That's why I was asking if it was an older model initially.

2h agoHN ↗

As another commenter pointed out, any cheapo ARM core from the last 10 years could do the job Flock needs it to do, as long as it has a (very cheap and common) crypto engine strapped to it.

But, a question for you: even if it was the case that the hardware was the limitation, isn't that also an indictment of Flock? Selling something that cannot exist securely within the bounds of current technology? Or, at a minimum, bad chip selection leading to a compromised design?

2h agoHN ↗

Yep. Clown show.

The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.

In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.

Source: https://www.404media.co/hackers-stole-flocks-camera-software...

2h agoHN ↗

TDIL my homebuilt Plex media server is more strongly encrypted than a Flock Camera

2h agoHN ↗

so is my all-passwords.txt file on my desktop

1h agoHN ↗

My passwords are in an encrypted block in a text file that can be unencrypted inline in an Emacs session with a keystroke sequence that looks like a cat just chased a mouse across the keyboard, and that's before entering the decryption password. To access it, an attacker would first have to learn Emacs. Pretty sure that's a post-quantum level of security.

42m agoHN ↗

It's a forever-fresh reminder about security versus your own government, but for malicious hackers and bots: the physical trip to visit you costs more than half their infrastructure.

Encryption matters, even if I would divulge everything long before the wrench appeared.

2h agoHN ↗

How could anyone possibly physically access a device that is just sitting out in public?

7m agoHN ↗

Runs Android. Has (wireless?) internet access.

It seems that some enterprising Jolly Roger could start running a public mesh net on top of them without Flock even noticing.

2h agoHN ↗

all that data is literally there for any unauthorized person to walk up and take it.

All that data about ... license plates if you're willing to steal/damage private property. Seems like it would be a lot easier to setup your own ALPR.

1h agoHN ↗

You don't think that because it's called a "license plate reader," that it only captures license plates, do you?

Flock cameras capture the make, model, color, and body style of vehicles. They capture bumper stickers and other decals, as well as potentially identifying dents and scratches. They capture accessories like roof racks, bike racks, trailers, and toolboxes.

The OP story covers some of this. There's more at:

https://www.aclu.org/campaigns-initiatives/get-the-flock-out

https://www.nytimes.com/2026/08/10/us/flock-cameras-can-trac...

15m agoHN ↗

License plate data is bad enough (and unconstitutional in many jurisdictions, despite ubiquity).

1h agoHN ↗

My working assumption based on what I hear out of Flock is that they have a public feature set (mass license plate surveillance for LEO) and a covert feature set (even more mass surveillance, beyond license plates and privacy agreements, for intelligence communities).

1h agoHN ↗

The man who would choose security over freedom deserves neither.

        -  Thomas Jefferson
1h agoHN ↗

Didn’t realize Jefferson misquoted Franklin

1h agoHN ↗

The devices are entirely open for all practical purposes - but worrying about individual cameras is silly, because they have no meaningful security at all around the API's to access all the cloud data - you can buy law enforcement credentials dirt cheap in dark web marketplaces to log in and track anyone/anywhere you want and access all footage.

3h agoHN ↗

Why did we not get the cool dystopia ala Gibson's Chiba City?

3h agoHN ↗

Because we got the gray box IBM version instead...

2h agoHN ↗

I remember walking over a hill into a rave in the Utah desert that we'd set up and thinking that it actually was the cyberpunk dystopia that I had been hoping for.

That kind of stuff is around but maybe not evenly distributed or legible to large demographics.

Unfortunately, so is the rest of the vicious horrorshow, equally illegible and equally uneven in distribution.

1h agoHN ↗

Interesting that you frame it as "hoping" for a dystopia. Like even in our wildest imaginations we can't envision a future where society works for regular folks.

34m agoHN ↗

it seems like all the tech-fascists just read snowcrash and settled on that.

3h agoHN ↗

Correct. YC gotta wear their creations with pride.

2h agoHN ↗

They won’t have that sort of moment of self reflection until someone does something like use Flock infrastructure to stalk and assassinate the CEO of another YC company and then it will only be brief and fleeting before they double down on supporting this kind of egregious behaviour.

Some people are just wired that way.

1h agoHN ↗

I say these people should not be in charge of choosing who gets insane amounts of money and networking opportunities

35m agoHN ↗

Let's just use Flock cameras to track all top-level YC people, publish everything we possibly can. Absolutely and utterly eliminate their privacy until they learn to respect ours.

3h agoHN ↗

I feel like most of this was already known when someone here in Dallas figured out they had wifi connectivity you could connect and get access. I may not have the details exactly correct but I think someone got access then.

3h agoHN ↗

Flock is a scourge on democracy. Flock is YC. But looks like they did YC nearly ten years ago. Who knows what their pitch deck looked like? If they pivoted since then to their current sinister incarnation? I don’t see any evidence that YC is still actively supporting them.

Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable proposition than funding Flock for their current use case of allowing police to stalk their ex girlfriends or mistresses.

2h agoHN ↗

Don't have the pitch deck directly, but do have some of the "what things looked like then" at https://www.ycdb.co/company/flock-safety

The front page then had "All the footage is yours. Your neighborhood 100% owns the data. Flock Safety will not share, sell, or access your data."

Unfortunately, flock has been excluded from wayback, so can't see other views of that page.

{insert Darth Vader: I'm altering the deal. Pray I don't alter it any further.}

(+45m edit) https://bestpitchdeck.com/flock-safety appears to be the pitch deck from 2020.

...

In 2019, Flock signed their first police department deal with Jersey Village, Texas.

The slides you see here are from Langley's pitch at a venture conference one month before closing a $47M Series C round in November 2020. The following July, Andreessen Horowitz led a $150M Series D investment in Flock as a cornerstone of their American Dynamism practice. Additional slides are included from keynote and sales presentations used in 2023.

...

2h agoHN ↗

It’s not like this stuff wasn’t known to be a problem 10 years ago. We were already in Trump’s first term, it’s not like it was part of the early post 9/11 “secure everything” push. It was WAY after that.

10 years ago is no excuse.

2h agoHN ↗

It’s not an excuse, but gives some luxury of distance. We have a lot more hindsight now on how rotten things can become, so with that hindsight it’s easy to say that companies like Flock shouldn’t exist, or shouldn’t be invested in. Ten years ago required some more leaps in foresight that some people were making, I was, but even I didn’t think it would get as evil as it has.

2h agoHN ↗

Flock is a scourge on democracy.

Yes. Blame the pickaxe seller. Do not question the miners. Do not question the investors in the mining companies. Do not question the casual voter or internet commenter who thought all this was fine.

This isn't to say that flock not a scourge, but I think a lot of people (not saying you're one of them) could stand to look in the mirror here.

Back in ye olde dark ages of <checks notes> 2017, when YC was cutting Flock a check and when "big data" was the hot buzzword people of a certain bent couldn't get enough of this kind of stuff. Everyone was jacking off nonstop to the idea that we could just hoover up everyone's data ad then "efficiently" or "proactively" dispatch enforcement resources. People talked all sorts of big talk about stuff like cross referencing people's Home Depot spend with permit requirements, identifying small businesses that don't have healthy enough financials to be fully compliant, cross referencing invoices and delivery receipts to identify overloaded trucks, and generally finding all sorts of ways to fine the crap out of people for the pettiest of petty deviance. They considered this a noble goal.

Everyone's head was too far up their asses to look at the magic crystal ball called "history" and realize that a camera on every street corner watching who's going where all the damn time would be where it goes.

3h agoHN ↗

If I had to guess now it works it would be:

1. Take pictures

2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes

Did I miss something

2h agoHN ↗

The system they log into is called DAVID(Driver and Automobile Information Database) which logs activity. If an officer access that information for unlawful purposes, they can be prosecuted. You probably wont believe it, but the reason you hear about cops stalking their ex's is because they got caught doing so.

2h agoHN ↗

How many didn't get caught? Or did but the issue was quietly "handled" within the department.

2h agoHN ↗

According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454.

Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1].

[1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes

2h agoHN ↗

That same NH law perhaps more importantly limits ALPR use to law enforcement officers.

2h agoHN ↗

Yes, only the unaccountable extra-judicial, legally immune low education, high domestic violence/divorce “law enforcement officers” should have access. It’s not like they would use it to stalk and surveil people … likes they have been caught doing all over and then get away with performative slaps on the wrist and get hired in the next jurisdiction down.

13m agoHN ↗

The images were deleted the moment they were uploaded. But the record in the log files persisted. The camera doesn't have enough memory to store that many data.

2h agoHN ↗

A friend in China built a Flock overlay network that sends live video and audio from ~100 cameras near me to an AWS server for processing and search.

1h agoHN ↗

This is one of the most interesting comments on here.

Hints at unauthorized, illegal mass surveillance riding on top of authorized (but also possibly illegal) mass surveillance

6m agoHN ↗

Can you provide more details? Do you mean 100 public cameras anyone can access?

2h agoHN ↗

"We liberated hardware"

Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.

2h agoHN ↗

And my privacy? The threat to democracy? Does Flock own that? Why is always the poors that need to own morality?

2h agoHN ↗

That's also the biggest plot-hole in the first Star Wars movie. Princess Leia is supposed to be this righteous noble of the moral resistance and yet she STEALS the Death Star plans!

2h agoHN ↗

I don't get the impression that anyone writing about this thinks it's legal. I think the argument would be that it's justified.

1h agoHN ↗

Then why bother using that language? The camera doesn't need rescuing, why not just "we took".

Also, is it really justified? Did we learn anything useful here that we didn't already know? There's more effective ways to push back against Flock, townships (like my own) are having plenty of success stories without stealing anything.

2h agoHN ↗

Anything becomes permissible when you believe yourself to be “on the right side of history.”

1h agoHN ↗

liberation is often used to refer to something that, while technically legal, the people that are subject to it did not agree to

1h agoHN ↗

This is pure laziness aka “reduced time to market” on the part of Flock.

It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.

Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.

Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.

Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.

1h agoHN ↗

The question is, why should they care at all? Will this hurt their business?

1h agoHN ↗

Is there any recent example of a company getting breached and its data exfiltrated, where the business was actually hurt? I predict we'll get a standard boilerplate "We take security very seriously" press release, a narrative that blames the evil hackers entirely and not the company's negligence, and then that will be that.

1h agoHN ↗

Quite potentially, yes. Their name is already mud among many voters, if they're shown to be treating data insecurely then that's another reason why local governments might consider terminating contracts with them.

1h agoHN ↗

Any breach of security on a system like this is a big flashing red-alert to me.

If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.

Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.

57m agoHN ↗

Apparently police are accessing the network via their personal devices. I highly doubt their security practices online are any better than this. I wouldn't be surprised either to see things that chinese manufacturers do such as intentional back doors.

Overall this goes from disappointing to fairly repugnant.

34m agoHN ↗

Allegedly you can buy credentials on the darkweb to perform national searches. Might explain why some of the logged reasons for recent searches were “LMAO”

19m agoHN ↗

The normal explanation is plenty, unless you’ve never met, read about, or heard anyone talk about, law enforcement officers (who are human beings - for better and for worse).

29m agoHN ↗

That's why you or I would care, but that doesn't answer the question of why they would.

Large companies tend to be amoral. Unless it affects them monetarily (possibly indirectly) they're not going to care. Given what they do to make money, I don't see any of these things hurting them.

55m agoHN ↗

Feels like their purpose is to test the boundaries, take the hits, and eventually sell off

47m agoHN ↗

I really hate how Product Managers somehow get to take the reins of engineering teams instead of having to sell them product ideas.

It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.

7m agoHN ↗

Because software engineering is not professional engineering.

Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult.

46m agoHN ↗

The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false.

If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.

1h agoHN ↗

I wonder if a stingray could be used to force a software update in a flock camera. If so maybe it could brick all the flock cameras it can connect to.

1h agoHN ↗

Yeah, you could potentially MITM them with a rogue cell tower, I suppose. I'm curious about the researchers still having the device. They could also see all the cloud endpoints that were being accessed. Are they secure?

1h agoHN ↗

If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP.

They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay.

Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.

And also, infrastructure vulnerabilities like DNS config - no no, try harder.

I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair.

https://www.flocksafety.com/legal/vulnerability-disclosure-p...

1h agoHN ↗

Curious how/why all this negative attention is focused directly on the Flock brand (current example notwithstanding)?

Seems like if I were a competitor of Flock I'd be pretty happy right now and all this negative press is making them artificially cheap to buyout right now.

Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this level of attention... not on the overarching issue of surveillance-state-ing, but of one particular company.

42m agoHN ↗

Flock has over 80% of the US market.

You've seen this level of attention on a market leader before: on Microsoft, on Adobe, and others.

1h agoHN ↗

I wonder if they were able to find any of the Bluetooth signal-data these cameras are said to be obtaining from devices within its' vicinity. This in itself is wild, im glad they're coming down around where I am

59m agoHN ↗

The article says that Flock says "their cameras don't do facial recognition" The cameras don't, but they don't say the system doesn't. They don't say facial recognition isn't a click away through another integration.

I would absolutely assume that any system that sends your image to LE is part of a facial recognition system in practice. We know now that the cameras do recognize people and intentionally transmits images of them, for later identification.

55m agoHN ↗

Commented something similar at the same time. I hate weasel wording like this. There is nothing that prevents this data from being used that way now or in the future.

edit: And to be clear, the cameras specifically recognize and record people for a reason. This does not appear to be a fault in the system. One reason might be off-camera facial recognition.

23m agoHN ↗

I’m sure the first approach has been ingesting vehicle registration data into Flock servers so that your ID photo pops up when your license is captured.

It seems the inevitable next step would be post-processed facial recognition (checked against those ready-for-the-taking ID photos) in their OS Investigator platform.

58m agoHN ↗

With that kind of protection it is guaranteed that that no Flock camera will ever be sold in Europe after december 2027... CRA et al...

I wonder what would happen if one of their customers asked for a 62443-4-2 certificate of compliance?

57m agoHN ↗

Interesting to note that if you don't look like a car or a person, through "adversarial fashion" or some other visual trick, your image potentially won't leave the camera and won't reach the flock cloud for further analysis.

50m agoHN ↗

It's surprising that an American company would forego so many common sense safety and security mechanisms just to protect their bottom line.

37m agoHN ↗

The other day I was imagining that everyone can just own any device near them. I suppose this implies that we have the resources and access to a capable model

24m agoHN ↗

All these cameras do is pre-select the images that are worthy uploading. Everything else happens at Flock.

That's why they don't give anything about the camera's security.

The images are all from a public place, so no privacy expectations and what's theworst that could happen? Someone uploads their cat images or the pr0n collection?

Ai figures that one out rather quickly.

10m agoHN ↗

Assuming the point of these cameras is security (and not just surveillance for stalker cops), being able to upload replacement footage would subvert that entirely. This has been a feature of many spy and cops/robber movies.

8m agoHN ↗

At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs.

When the camera did restart, another service left a final message in the logs: “A reboot was requested! ¡Adiós, Amigos!”

Cool, so they were programmed by someone with the maturity of a teenager.